diff --git a/pkg/complianceportal/visitor/portal_access_service.go b/pkg/complianceportal/visitor/portal_access_service.go index fb51d9c26..4f5b705e3 100644 --- a/pkg/complianceportal/visitor/portal_access_service.go +++ b/pkg/complianceportal/visitor/portal_access_service.go @@ -35,9 +35,6 @@ import ( "go.probo.inc/probo/pkg/page" ) -// PortalAccessRequest carries the explicit resource IDs to request access for. -// Callers must supply at least one ID across the three slices; nil and empty -// both mean "none of that type" (there is no "request all" expansion). type PortalAccessRequest struct { CompliancePortalID gid.GID IdentityID gid.GID diff --git a/pkg/server/api/complianceportal/v1/compliance_portal_resolvers.go b/pkg/server/api/complianceportal/v1/compliance_portal_resolvers.go index fecec4373..50bb16ce2 100644 --- a/pkg/server/api/complianceportal/v1/compliance_portal_resolvers.go +++ b/pkg/server/api/complianceportal/v1/compliance_portal_resolvers.go @@ -1001,13 +1001,6 @@ func (r *mutationResolver) RequestReportAccess(ctx context.Context, input types. return nil, gqlutils.Internal(ctx) } - // GetAuditByReportFileID is only tenant-scoped, so a report belonging to - // another organization in the same tenant would otherwise be reachable. - // Reject it as not found before an access row can be written. - if audit.OrganizationID != compliancePortal.OrganizationID { - return nil, gqlutils.NotFoundf(ctx, "report %q not found", input.ReportID) - } - if audit.CompliancePortalVisibility == coredata.CompliancePortalVisibilityPublic { return nil, gqlutils.Invalidf( ctx, @@ -1156,13 +1149,6 @@ func (r *mutationResolver) RequestAccesses(ctx context.Context, input types.Requ return nil, gqlutils.Internal(ctx) } - // GetAuditByReportFileID is only tenant-scoped, so a report belonging to - // another organization in the same tenant would otherwise be reachable. - // Reject it as not found before an access row can be written. - if audit.OrganizationID != compliancePortal.OrganizationID { - return nil, gqlutils.NotFoundf(ctx, "report %q not found", reportID) - } - if audit.CompliancePortalVisibility == coredata.CompliancePortalVisibilityPublic { continue }