privacy/security: add PM privacy levels and improve session visibility
All checks were successful
CI / test (push) Successful in 24s
All checks were successful
CI / test (push) Successful in 24s
This commit is contained in:
@@ -29,6 +29,7 @@ from app.messages.repository import (
|
||||
)
|
||||
from app.realtime.presence import get_users_online_map
|
||||
from app.users.repository import get_user_by_id, has_block_relation_between_users, is_user_in_contacts
|
||||
from app.users.service import can_user_receive_private_messages
|
||||
|
||||
|
||||
async def _can_view_last_seen(*, db: AsyncSession, target_user, viewer_user_id: int) -> bool:
|
||||
@@ -177,7 +178,7 @@ async def create_chat_for_user(db: AsyncSession, *, creator_id: int, payload: Ch
|
||||
)
|
||||
if payload.type == ChatType.PRIVATE:
|
||||
target_user = await get_user_by_id(db, member_ids[0])
|
||||
if target_user and not target_user.allow_private_messages:
|
||||
if target_user and not await can_user_receive_private_messages(db, target_user=target_user, actor_user_id=creator_id):
|
||||
raise HTTPException(
|
||||
status_code=status.HTTP_403_FORBIDDEN,
|
||||
detail="User does not accept private messages",
|
||||
|
||||
Reference in New Issue
Block a user