🧾 fix: Harden Historical File Authorization (#13918)

* fix: Harden historical file authorization

* chore: Sort file authorization imports

* fix: Preserve authorized historical artifact refs

* chore: Format historical artifact hardening
This commit is contained in:
Danny Avila 2026-06-23 15:49:57 -04:00 committed by GitHub
parent 606292c5c5
commit 1eb460eb03
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
11 changed files with 755 additions and 74 deletions

View file

@ -305,10 +305,14 @@ const pruneToolResourceFileIdsForOwner = async ({ tool_resources, ownerId, logPr
const ownerIdStr = ownerId.toString();
try {
const ownerFiles = await db.getFiles({ file_id: { $in: referencedFileIds } }, null, {
file_id: 1,
user: 1,
});
const ownerFiles = await db.getFiles(
{ file_id: { $in: referencedFileIds }, user: ownerIdStr },
null,
{
file_id: 1,
user: 1,
},
);
const allowedIds = new Set(
(ownerFiles ?? [])
.filter((file) => file.user && file.user.toString() === ownerIdStr)