opensafely-core / airlock

Other
1 stars 0 forks source link

Output-checker can't delete comment if they don't have access to the workspace #540

Closed rebkwok closed 1 month ago

rebkwok commented 1 month ago

If an output-checker doesn't have access to the request's workspace, they can create a comment, but can't delete it.

In group_comment_delete, the check for the comment author is there, but we should not check for workspace permission