From f0f9b7faecdf0f68f5c9d75312c9e9613b0bd730 Mon Sep 17 00:00:00 2001 From: Ulf Gebhardt Date: Mon, 19 Jan 2026 19:14:17 +0100 Subject: [PATCH] fix(backend): fix permissions for GroupInviteCodes (#9121) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Wolfgang Huß --- backend/src/middleware/permissionsMiddleware.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/src/middleware/permissionsMiddleware.ts b/backend/src/middleware/permissionsMiddleware.ts index 5fc087204..0e85a43af 100644 --- a/backend/src/middleware/permissionsMiddleware.ts +++ b/backend/src/middleware/permissionsMiddleware.ts @@ -387,7 +387,7 @@ const isAllowedToGenerateGroupInviteCode = rule({ return !!( await context.database.query({ query: ` - MATCH (user:User{id: user.id})-[membership:MEMBER_OF]->(group:Group {id: $args.groupId}) + MATCH (user:User{id: $user.id})-[membership:MEMBER_OF]->(group:Group {id: $args.groupId}) WHERE (group.type IN ['closed','hidden'] AND membership.role IN ['admin', 'owner']) OR (NOT group.type IN ['closed','hidden'] AND NOT membership.role = 'pending') RETURN count(group) as count