fix: filter on is_active in channel membership checks (#23623)

is_user_channel_member and is_user_channel_manager did not filter on is_active, allowing deactivated members to retain read/write access to group channels via direct API calls.
This commit is contained in:
Classic298
2026-04-12 11:13:51 -05:00
committed by GitHub
parent 5eab125f13
commit 71a39dbac1
+2
View File
@@ -508,6 +508,7 @@ class ChannelTable:
.filter(
ChannelMember.channel_id == channel_id,
ChannelMember.user_id == user_id,
ChannelMember.is_active.is_(True),
ChannelMember.role == 'manager',
)
.first()
@@ -667,6 +668,7 @@ class ChannelTable:
.filter(
ChannelMember.channel_id == channel_id,
ChannelMember.user_id == user_id,
ChannelMember.is_active.is_(True),
)
.first()
)