Merge pull request #1697 from denkfabrik-li/fix/assigned-clients-authority

Nobody hands out reach they do not hold either

Two resolutions against branches that landed first. #1678 and this one
each add a constructor property and an import to StaffAccounts, so both
are kept. And #1702's merge note called this one exactly: its
"converting an account to staff cannot hand out clients either" case
promoted a stranger client, which #1702 now refuses at 404 before
validation runs. Pointed at a client the actor holds, as that note
proposed, so the request reaches the assigned_clients rule the case is
actually about.
This commit is contained in:
ignacionelson
2026-08-26 22:35:35 -03:00
6 changed files with 276 additions and 10 deletions
+4 -2
View File
@@ -3240,7 +3240,8 @@
"assigned_clients": {
"type": "array",
"items": {
"type": "integer"
"type": "integer",
"description": "Only clients you can reach yourself: an unrestricted account may\nassign any client, a client-scoped one only the clients already\nassigned to it. Assigning a client hands over everything that\nclient can see, so it follows the same rule as role_id above."
}
}
},
@@ -3376,7 +3377,8 @@
"assigned_clients": {
"type": "array",
"items": {
"type": "integer"
"type": "integer",
"description": "Only clients you can reach yourself: an unrestricted account may\nassign any client, a client-scoped one only the clients already\nassigned to it. Assigning a client hands over everything that\nclient can see, so it follows the same rule as role_id above."
}
}
}