[PR #315] [MERGED] Restrict join on users_collections to current user (fixes #313) #3751

Closed
opened 2025-10-09 18:29:25 +03:00 by OVERLORD · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/dani-garcia/vaultwarden/pull/315
Author: @aksdb
Created: 12/28/2018
Status: Merged
Merged: 12/28/2018
Merged by: @dani-garcia

Base: masterHead: master


📝 Commits (1)

  • e7ea509 Restrict join on users_collections to current user (fixes #313)

📊 Changes

1 file changed (+7 additions, -3 deletions)

View changed files

📝 src/db/models/cipher.rs (+7 -3)

📄 Description

It fixes #313 at least partially ... the other part being fixed by @mprasil's PR #314.

The problem was, that when multiple users in the same collection are Admin or Owner, the previous JOIN would include multiple rows for the same cipher. The PR fixes this by restricting the joined users_collections in the first place.
(It also makes another JOIN a little more explicit.)


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/dani-garcia/vaultwarden/pull/315 **Author:** [@aksdb](https://github.com/aksdb) **Created:** 12/28/2018 **Status:** ✅ Merged **Merged:** 12/28/2018 **Merged by:** [@dani-garcia](https://github.com/dani-garcia) **Base:** `master` ← **Head:** `master` --- ### 📝 Commits (1) - [`e7ea509`](https://github.com/dani-garcia/vaultwarden/commit/e7ea5097f49bb1f42ffdb59a038a02fea093df10) Restrict join on users_collections to current user (fixes #313) ### 📊 Changes **1 file changed** (+7 additions, -3 deletions) <details> <summary>View changed files</summary> 📝 `src/db/models/cipher.rs` (+7 -3) </details> ### 📄 Description It fixes #313 at least partially ... the other part being fixed by @mprasil's PR #314. The problem was, that when multiple users in the same collection are Admin or Owner, the previous JOIN would include multiple rows for the same cipher. The PR fixes this by restricting the joined users_collections in the first place. (It also makes another JOIN a little more explicit.) --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
OVERLORD added the pull-request label 2025-10-09 18:29:25 +03:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/vaultwarden#3751