package api import ( "archivmail/internal/auth" ) // tenantAccessAllowed checks whether the given session may access an IMAP/POP3 // account belonging to accTenantID. Superadmins (sess.TenantID == nil) may // access any tenant. Other admins may only access accounts within their own // tenant (accTenantID must be set and match). func tenantAccessAllowed(sess *auth.Session, accTenantID *int64) bool { if sess.TenantID == nil { return true } return accTenantID != nil && *accTenantID == *sess.TenantID }