•  
      request #41867 check every sections are readable before POST
    Infos
    #41867
    Nicolas Terray (nterray)
    2025-02-26 14:36
    2025-02-24 15:35
    43543
    Details
    check every sections are readable before POST

    Artidoc can be composed by different artifacts. Some can be unreadable to the current user (ex: perms on artifcat). In that case, in order to not present a document with only part of the information, it has been decided that the document content would not be displayed at all, even if user has right permissions on the document itself.

    Therefore we should check at the API level that all existing sections are readable before creating a new one.

    Artidoc
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Nicolas Terray (nterray)
    Closed
    2025-02-24
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-02-26 14:36

    Disclosing, while this lacked consistency it did not really expose information nor permitted a user without write permissions to break the artidoc in ways they could not already do.