The GitHub Actions job "Backport Checks" on 
texera.git/fix/readonly-write-controls has succeeded.
Run started by GitHub user tanishqgandhi1908 (triggered by tanishqgandhi1908).

Head commit for run:
de67a8e6ba1a583c68e73bb2fe47f7d010b2e074 / Tanishq Gandhi 
<[email protected]>
feat(frontend): gate the file tree's delete and cover controls on write access

A collaborator with READ access saw write controls in the file tree. Nothing
insecure happened, since the backend rejects the calls, but the buttons should
not be offered: the dataset page bound isTreeNodeDeletable to true
unconditionally, and the shared file tree gated "Set as cover" on the file
being an image and nothing else, so both the dataset and the model page offered
it to readers. Clicking it returned a 403 toast.

Add an isCoverSettable input defaulting to false, like isTreeNodeDeletable
beside it, and have both detail pages bind their own write-access check. The
dataset-selection-modal binds neither input, so the cover button it never wired
up no longer renders.

Closes #8349.

Report URL: https://github.com/apache/texera/actions/runs/33680252090

With regards,
GitHub Actions via GitBox

Reply via email to