mirror of
https://github.com/bitwarden/server
synced 2026-01-05 01:53:17 +00:00
refactor subvault ctrl with org context checks
This commit is contained in:
@@ -1,19 +0,0 @@
|
||||
CREATE PROCEDURE [dbo].[Subvault_ReadByIdAdminUserId]
|
||||
@Id UNIQUEIDENTIFIER,
|
||||
@UserId UNIQUEIDENTIFIER
|
||||
AS
|
||||
BEGIN
|
||||
SET NOCOUNT ON
|
||||
|
||||
SELECT
|
||||
S.*
|
||||
FROM
|
||||
[dbo].[SubvaultView] S
|
||||
INNER JOIN
|
||||
[OrganizationUser] OU ON OU.[OrganizationId] = S.[OrganizationId]
|
||||
WHERE
|
||||
S.[Id] = @Id
|
||||
AND OU.[UserId] = @UserId
|
||||
AND OU.[Status] = 2 -- Confirmed
|
||||
AND OU.[Type] <= 1 -- Owner and admin
|
||||
END
|
||||
@@ -1,19 +0,0 @@
|
||||
CREATE PROCEDURE [dbo].[Subvault_ReadByOrganizationIdAdminUserId]
|
||||
@OrganizationId UNIQUEIDENTIFIER,
|
||||
@UserId UNIQUEIDENTIFIER
|
||||
AS
|
||||
BEGIN
|
||||
SET NOCOUNT ON
|
||||
|
||||
SELECT
|
||||
S.*
|
||||
FROM
|
||||
[dbo].[SubvaultView] S
|
||||
INNER JOIN
|
||||
[OrganizationUser] OU ON OU.[OrganizationId] = S.[OrganizationId]
|
||||
WHERE
|
||||
S.[OrganizationId] = @OrganizationId
|
||||
AND OU.[UserId] = @UserId
|
||||
AND OU.[Status] = 2 -- Confirmed
|
||||
AND OU.[Type] <= 1 -- Owner and admin
|
||||
END
|
||||
Reference in New Issue
Block a user