8000 Removing doc permission inherited from parent : doc title continue to exist to non-granted users. (Not expected) · Issue #8290 · outline/outline · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Removing doc permission inherited from parent : doc title continue to exist to non-granted users. (Not expected) #8290

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
2 tasks done
thomas-zic opened this issue Jan 23, 2025 · 4 comments

Comments

@thomas-zic
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

This is not related to configuring Outline

  • The issue is not related to self-hosting config

Current Behavior

Use Case

  1. Create a ‘Projects’ collection with "No access" permission
  2. Create a ‘Project A’ document
  3. Give permission to the T1 group (e.g. Read only)
  4. Create a ‘Hello A’ document in ‘Project A’
  5. View the permissions for the ‘Hello A’ document.
  6. Remove the ‘Has access through parent’ permission.

Image

This is what the administrator sees for the ‘Projects’ collection.
As he has access to everything, he is obviously able to see the ‘Hello A’ document in the tree and its contents.
Image

Following the removal of the permission inherited to ‘Project A’ for the document ‘Hello A’ as below:
Image

This is what the test user sees for the ‘Projects’ collection.
We can see that he continues to see the ‘Hello A’ document in the tree structure even though he has lost access to it.
This is not logical. However, he can no longer consult its contents, as indicated by the ‘Not found’ message.
Image

Expected Behavior

The test user no longer has access to the ‘Hello A’ document at all.
Logically, it should no longer be part of the tree structure for the test user:
Image

Confidential information may be present in the name of a document ( i.e. a customer name, any ID, etc.).

Steps To Reproduce

No response

Environment

Anything else?

No response

@thomas-zic thomas-zic added the bug label Jan 23, 2025
Copy link
linear bot commented Jan 23, 2025

@tommoor
Copy link
Member
tommoor commented Jan 23, 2025

This is just a local cache, probably fixed by #7745

@thomas-zic
Copy link
Author

Will the fix be available in the next update ?

Copy link
Contributor

This issue is stale because it has been open 90 days with no activity. Remove stale label or comment or this will be closed in 5 days

@github-actions github-actions bot added the stale label May 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants
0