Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-25159

Access rights cannot be checked at query time, so counts, pagination and tree state don't take rights into account

    XMLWordPrintable

Details

    • Improvement
    • Resolution: Unresolved
    • Major
    • None
    • None
    • None
    • None
    • Unknown

    Description

      This is the generic root cause for multiple bugs reported (see XWIKI-18601)

       

      XWiki's authorization is computed at read time (it supports nesting and inheritance), so access rights cannot be evaluated as part of a database query or a Solr query. As a result, every query-based UI (page tree, LiveTable, search, facets, index) retrieves results first and filters them by view right afterwards. This produces a family of inconsistent behaviours: wrong counts, broken pagination, facets that count or name hidden documents, and tree nodes (e.g. expand arrows) that hint at content the current user cannot see.

      Expected result: Query-based UIs should reflect the current user's view right consistently in: the result list, the total count, the pagination, facet values/counts, and any structural affordance (e.g. tree expand arrows).

      Steps to reproduce:
      1. Create a public page A under the default Dashboard (visible in the left navigation).

      2. Create a child page B of A and remove its view right for some group/user.

      3. As a user in that group, observe:

      • the navigation tree still shows an expand arrow on A (XWIKI-18601);
      • where the same setup is used in a search/LiveTable, counts and pagination are wrong (XWIKI-8583, XWIKI-9649).

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              ecojocariu Eleni
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated: