Fix invitations by regular occupants in members-only rooms - #3457
Open
sangbingxing wants to merge 1 commit into
Open
Fix invitations by regular occupants in members-only rooms#3457sangbingxing wants to merge 1 commit into
sangbingxing wants to merge 1 commit into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughMembers-only room invitations now delegate invitee membership assignment to Suggested reviewers: 🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A regular room occupant can pass the invitation authorization check when
muc#roomconfig_allowinvitesis enabled. In a members-only room, Openfire then tries to add the invitee as a member using the inviter'smemberaffiliation.MUCRoom.addMemberrequires an admin or owner affiliation, which rejects the invitation withforbidden.Change
When occupant invitations are enabled, add the invitee on behalf of the room, whose self-representation has owner affiliation. When occupant invitations are disabled, retain the inviter's affiliation so the existing admin/owner permission check remains in effect. The actual inviter JID and affiliation are still passed to
sendInvitation.Add regression coverage for both configuration states.
Testing
mvnw.cmd -pl xmppserver -am -Dtest=MultiUserChatServiceImplTest -Dsurefire.failIfNoSpecifiedTests=false testmvnw.cmd -pl xmppserver -am test(2068 tests, 0 failures, 0 errors, 3 skipped)