Skip to content

Validate group collaboration invitees before reading conversation history (0.261.259) - #1656

Merged
Paul Lizer (paullizer) merged 2 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-collaboration-invitee-validation-order
Oct 6, 2026
Merged

Paul Lizer (paullizer) merged 2 commits into
microsoft:paullizer-react-v2-uifrom
paullizer:paullizer-collaboration-invitee-validation-order

Conversation

@paullizer

@paullizer Paul Lizer (paullizer) commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Converting an existing group conversation into a shared conversation now checks every invitee against the group's current membership before it prepares Microsoft 365 history publication or reads the transcript. An invitee outside the group is still rejected with nothing changed, but the rejection now happens before any message history is queried.
  • test_group_document_collaboration.py replaced functions_workflow_alert_safety with a stub that lacked the three constants functions_workflow_alerts now imports, so the suite stopped during fixture setup. The stub now exports them, and the sharing and repair checks run again.

Linked issue

Fixes #1651

Release Notes & Latest Features

  • New Feature
  • Bug Fix
  • UI Enhancement
  • Breaking Change
  • Internal only

Is this visible to end users?

  • Yes
  • No (the same requests are rejected with the same response; only the order of checks changes)

Is this admin-facing (Admin Settings, governance, deployment, config)?

  • Yes
  • No

Should this become a Latest Feature card?

  • Yes
  • No
  • Already added

Screenshot needed for the card?

  • Yes
  • No
  • Attached

Version bump

Testing / validation

  • pytest functional_tests/test_group_collaboration_source_storage_fix.py: 20 passed, 106 subtests passed. On the base, the four non_group_invitee subtests fail because the message container is queried before the rejection.
  • pytest "functional_tests/test_group_document_collaboration.py::test_sharing_mutations_require_current_selected_group_managers[owner-share]": passes; on the base its setup fails with ImportError for WORKFLOW_ALERT_EVALUATION_ERROR_CODE. The full document-collaboration matrix was not run to completion locally.
  • test_docs_app_surface_coverage.py (7/7) and test_docs_site_quality.py (6/6)
  • scripts/check_broken_access_control.py application/single_app/functions_collaboration.py --full-file

Documentation

  • Release notes updated, or not needed (0.261.259)
  • Feature documentation updated, or not needed (not needed)
  • Fix documentation updated, or not needed: docs/explanation/fixes/GROUP_COLLABORATION_INVITEE_VALIDATION_ORDER_FIX.md

Security checklist

  • New Flask routes include @swagger_route(security=get_auth_security()) (no new routes)
  • Settings sent to non-admin frontends use sanitize_settings_for_user() (no settings sent)
  • Browser JavaScript is served from local SimpleChat static assets only; no CDN-hosted JS (no browser changes)
  • No secrets, keys, connection strings, or local-only artifacts are included

…tory

Group conversation conversion now checks every invitee against current group membership before preparing Microsoft 365 history publication or reading the transcript. The group document collaboration fixture exports the current workflow alert safety constants. Refs microsoft#1651.
@paullizer Paul Lizer (paullizer) changed the title Validate group collaboration invitees before reading conversation history (0.261.258) Validate group collaboration invitees before reading conversation history (0.261.259) Oct 6, 2026
@paullizer
Paul Lizer (paullizer) merged commit 1b8d4c4 into microsoft:paullizer-react-v2-ui Oct 6, 2026
10 checks passed
Paul Lizer (paullizer) added a commit that referenced this pull request Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants