aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/groups.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/groups.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/groups.py7
1 files changed, 7 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/groups.py b/packages/meshbay-hub/src/meshbay_hub/api/groups.py
index fdb0444..07d3ec0 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/groups.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/groups.py
@@ -589,6 +589,13 @@ async def add_group_member(
current_user: User = Depends(get_current_user),
db: AsyncSession = Depends(get_db),
):
+ # `get_current_user`, not `require_user_scope`: the node calls this after a
+ # CLI `member invite` so the group becomes visible in the invitee's SPA
+ # (commit 0443cf8). The node authenticates with a node-scoped token, and the
+ # `group.admin_id == current_user.id` check below is the real guard — a node
+ # can only touch its own operator's groups, adding an already-registered
+ # account. (Third-review M6 proposed tightening this to `require_user_scope`;
+ # that broke the CLI invite flow and was reverted — see the review doc.)
group = await db.get(Group, group_id)
if not group:
raise HTTPException(status_code=404, detail="Group not found")