8000 Sometimes private collections are visible to admins · Issue #3454 · outline/outline · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Sometimes private collections are visible to admins #3454

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
gemathus opened this issue Apr 25, 2022 · 6 comments · Fixed by #5273
Closed

Sometimes private collections are visible to admins #3454

gemathus opened this issue Apr 25, 2022 · 6 comments · Fixed by #5273
Labels
bug pinned Will not be closed by stale bot

Comments

@gemathus
Copy link
Contributor

I've experienced this issue twice: a non admin user creates a collection and removes read and write access to all (making the collection private). Now, me, as an admin user, logged into our self deployed Outline and was able to see this user's private collection and documents. After refreshing the page, the collection was no longer visible to me.

To Reproduce
I don't know yet... We've only experienced this issue twice in the last month without any clear reproduction steps. I will keep a look out in our dev environment to try to catch it in the logs.

Expected behavior
Private documents should not be visible to anyone, including admin users.

Outline (please complete the following information):

  • Install: self hosted
  • Version: v0.63.0

Desktop (please complete the following information):

  • OS: Mac OS
  • Browser Chrome
  • Version 100.0.4896.127 (Official Build) (arm64)
@gemathus gemathus added the bug label Apr 25, 2022
@tommoor
Copy link
Member
tommoor commented Apr 25, 2022

It was recently changed so that admins have read permissions to collections if the id is known, so I suspect this is related – although it is indicative of a possible wider bug where permissions are not correctly propagated perhaps?

Ideally we'd allow admins to see the existence and manage private collections but not read the content without being added explicitly as a member either by themselves or someone else. This will mean separating the permission that currently encompasses both.

@gemathus
Copy link
Contributor Author

Right, I had noticed that read access was granted to admins given the full url. Nonetheless, this happened while I was in another document/collection, and I had not previously accessed this private collection, it just showed up on my sidebar.

I will try to reproduce this in the next couple of days, and keep you posted.

@tommoor tommoor changed the title Sometimes private collections are visible to users without read nor write access Sometimes private collections are visible to admins Apr 25, 2022
@github-actions
Copy link
Contributor

This issue is stale because it has been open 90 days with no activity. Remove stale label or comment or this will be closed in 5 days

@github-actions github-actions bot added the stale label Aug 24, 2022
@github-actions
Copy link
Contributor

Automatically closed due to inactivity

@ChuckJonas
Copy link
Contributor

I just experience this bug. Another admin created a collection with "No Access", and only themselves added with Read/Write Permissions. I was able to see this collection for a few minutes and then it disappeared...

As an Admin/User, I still do not want to see everyones private collections, as this makes my end user experience terrible.

@tommoor tommoor reopened this Jan 11, 2023
@github-actions github-actions bot removed the stale label Jan 11, 2023
@tommoor tommoor added the pinned Will not be closed by stale bot label Jan 29, 2023
@thumDer
Copy link
thumDer commented Mar 31, 2023

Also, if there is a collection with view-only default permission, I can edit its pages, even if I don't have explicit edit permission. It is a bit inconsistent. However, as an admin, there are cases where I wan't to see all of the collections (even private ones).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug pinned Will not be closed by stale bot
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants
0