forked from Yara724/api
fix claim validation and expert branch scoping
This commit is contained in:
@@ -614,9 +614,24 @@ export class ExpertBlameService {
|
||||
)) as Record<string, unknown>[];
|
||||
|
||||
// Scope to this reviewer's insurance company via blame party clientId
|
||||
const visibleCases = allSealed.filter((doc) =>
|
||||
const tenantVisibleCases = allSealed.filter((doc) =>
|
||||
blameCaseTouchesClient(doc, clientKey),
|
||||
);
|
||||
const visibleCases = (
|
||||
await Promise.all(
|
||||
tenantVisibleCases.map(async (doc) => {
|
||||
try {
|
||||
await this.requestManagementService.assertFileReviewerBranchAccess(
|
||||
doc,
|
||||
actor.sub,
|
||||
);
|
||||
return doc;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}),
|
||||
)
|
||||
).filter((doc): doc is Record<string, unknown> => doc != null);
|
||||
|
||||
const pagedResult = await this.paginateBlameListV2(visibleCases, query);
|
||||
return pagedResult;
|
||||
|
||||
Reference in New Issue
Block a user