fix: A16 — ACL sur l'export et les pièces jointes (v7.3.4)
FlowDeck CI / docker (push) Successful in 1m44s
FlowDeck CI / lint (push) Successful in 1m49s
FlowDeck CI / test (push) Successful in 21m5s

- `export.py` : `_load_page_or_404(request, page_id)` — 401 sans session,
  404 si `PermissionManager.can_view_page` refuse (les 4 formats d'export)
- `dashboard.py` : helper `_require_page_view` sur `GET /api/pages/{id}/download`
  et `GET /api/pages/{id}/file-content`
- +1 test de non-régression → suite **1026/1026**, `ruff check app tests` OK
This commit is contained in:
2026-09-30 23:20:26 -04:00
parent 5a537f5dc3
commit 72fcef2ba9
8 changed files with 57 additions and 12 deletions
+11
View File
@@ -97,3 +97,14 @@ def test_upload_requires_session_and_validates_files(client):
anon(client)
r = client.post("/api/local-workspace/upload", files={"files": ("a.txt", b"x", "text/plain")})
assert r.status_code == 401
def test_exports_and_attachments_require_auth(client):
"""A16 : export + pièces jointes = session et `can_view_page` (jamais le contenu)."""
pid = client.post("/board/api/pages?title=Secret&section=Private").json()["id"]
anon(client)
assert client.get(f"/api/export/markdown/{pid}").status_code == 401
assert client.get(f"/api/export/html/{pid}").status_code == 401
assert client.get(f"/api/pages/{pid}/download").status_code == 401
assert client.get(f"/api/pages/{pid}/file-content").status_code == 401