fix(api): let channel managers edit a mature channel (#2583)

This commit is contained in:
Hampus
2026-09-08 14:51:47 +02:00
committed by GitHub
parent 2019909a5e
commit a2a68847fd
6 changed files with 44 additions and 35 deletions
@@ -123,6 +123,7 @@ export function ChannelController(app: HonoApp) {
const existing = await ctx.get('channelService').channelData.operations.getChannel({
userId: ctx.get('user').id,
channelId,
skipNsfwValidation: true,
});
ctx.set('channelUpdateType', existing.type);
return undefined;
@@ -111,7 +111,7 @@ export class ChannelDataService {
clientFeatures: ReadonlySet<string>;
requestCache: RequestCache;
}): Promise<Channel> {
const {channel} = await this.auth.getChannelAuthenticated({userId, channelId});
const {channel} = await this.auth.getChannelAuthenticated({userId, channelId, skipNsfwValidation: true});
if (channel.type === ChannelTypes.GROUP_DM) {
return await this.groupDmUpdate.updateGroupDmChannel({
userId,
@@ -90,8 +90,20 @@ export class ChannelOperationsService {
private rateLimitService: IRateLimitService,
) {}
async getChannel({userId, channelId}: {userId: UserID; channelId: ChannelID}): Promise<Channel> {
const {channel} = await this.channelAuthService.getChannelAuthenticated({userId, channelId});
async getChannel({
userId,
channelId,
skipNsfwValidation,
}: {
userId: UserID;
channelId: ChannelID;
skipNsfwValidation?: boolean;
}): Promise<Channel> {
const {channel} = await this.channelAuthService.getChannelAuthenticated({
userId,
channelId,
skipNsfwValidation,
});
return channel;
}
@@ -127,6 +139,7 @@ export class ChannelOperationsService {
const {channel, guild, checkPermission} = await this.channelAuthService.getChannelAuthenticated({
userId,
channelId,
skipNsfwValidation: true,
});
if (channel.type === ChannelTypes.GROUP_DM) {
throw new InvalidChannelTypeError();
@@ -456,7 +469,11 @@ export class ChannelOperationsService {
if (this.voiceAvailabilityService === null) {
return [];
}
const {channel, guild} = await this.channelAuthService.getChannelAuthenticated({userId, channelId});
const {channel, guild} = await this.channelAuthService.getChannelAuthenticated({
userId,
channelId,
skipNsfwValidation: true,
});
if (channel.type !== ChannelTypes.GUILD_VOICE) {
throw new InvalidChannelTypeError();
}
@@ -46,6 +46,18 @@ describe('Channel Operation Permissions', () => {
.expect(HTTP_STATUS.FORBIDDEN)
.execute();
});
it('should let a minor manage a mature channel without reading it', async () => {
const owner = await createTestAccount(harness, {dateOfBirth: '2010-01-01'});
const guild = await createGuild(harness, owner.token, 'Mature Channel Guild');
const systemChannel = await getChannel(harness, owner.token, guild.system_channel_id!);
await updateChannel(harness, owner.token, systemChannel.id, {nsfw: true});
const renamed = await updateChannel(harness, owner.token, systemChannel.id, {name: 'still-manageable'});
expect(renamed.name).toBe('still-manageable');
await createBuilder(harness, owner.token)
.get(`/channels/${systemChannel.id}/messages`)
.expect(HTTP_STATUS.FORBIDDEN)
.execute();
});
it('should reject member from updating channel without MANAGE_CHANNELS', async () => {
const owner = await createTestAccount(harness);
const member = await createTestAccount(harness);