Fix individual gallery access for location-based roles - #1780
Closed
JasonWildMe wants to merge 1 commit into
Closed
JasonWildMe wants to merge 1 commit into
JasonWildMe wants to merge 1 commit into
Conversation
Add a location-role fallback when indexed encounter permissions lag, using the current database location. Cover stale permissions and denied access with regression tests. Implemented by OpenAI Codex; independently reviewed by Claude.
JasonWildMe
marked this pull request as draft
September 30, 2026 19:57
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1780 +/- ##
========================================
Coverage 54.89% 54.89%
========================================
Files 314 314
Lines 12717 12717
Branches 4122 4013 -109
========================================
Hits 6981 6981
Misses 5441 5441
Partials 295 295
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A researcher with valid location-based roles can open an individual’s View all images gallery and receive zero or only some images when OpenSearch’s indexed
viewUserslist has not caught up. Search sanitization marks those encounters asaccess: noneand removes their media, even though the live location-role checks grant access. This mismatch provides a code-level explanation for the progressive image counts reported in #1779; it has not been verified against the affected production account.OpenSearch.sanitizeDocnow checks the researcher’s live location roles when an indexed permission check denies a browser encounter-search hit. It loads the encounter’s current database location and uses the existingLocationRoleAccessrules, including ancestor roles. This makes gallery visibility independent of stale location-role entries in the index. Missing encounters and nonmatching roles remain denied. Token searches retain their query-time indexed permission filtering.Fixes #1779.
Validation
mvn -o test -Dtest=SearchLocationRoleAccessTest,OpenSearchSanitizeDocTest,OpenSearchAclFilterTest,OpenSearchAclFilterIndexAwareTest,LocationRoleAccessTest,LocationRoleEncounterAccessTest,LocationRoleViewUsersTest,LocationRolePermissionsPassTest,LocationIDLineageTest.Implementation and review
Implemented and tested by OpenAI Codex. Claude independently reviewed a snapshot of the patch and relevant code and reported no blocking findings. Claude did not run the tests or reproduce the issue in production. Its review noted additional database lookups for denied browser-search hits, which may affect broad searches; this PR keeps the fallback limited to hits that indexed permissions deny. An outdated overload comment identified in review was corrected.
This change addresses the browser gallery’s location-role fallback. It does not eliminate background indexing lag or change token-search, collaboration, or organization-grant behavior. Database role-query errors remain request errors rather than silently returning an incomplete gallery.
No UI strings or dependencies changed.