Skip to content

Fix individual gallery access for location-based roles - #1780

Closed
JasonWildMe wants to merge 1 commit into
mainfrom
fix/1779-gallery-location-role-access
Closed

JasonWildMe wants to merge 1 commit into
mainfrom
fix/1779-gallery-location-role-access

Conversation

@JasonWildMe

Copy link
Copy Markdown
Collaborator

A researcher with valid location-based roles can open an individual’s View all images gallery and receive zero or only some images when OpenSearch’s indexed viewUsers list has not caught up. Search sanitization marks those encounters as access: none and removes their media, even though the live location-role checks grant access. This mismatch provides a code-level explanation for the progressive image counts reported in #1779; it has not been verified against the affected production account.

OpenSearch.sanitizeDoc now checks the researcher’s live location roles when an indexed permission check denies a browser encounter-search hit. It loads the encounter’s current database location and uses the existing LocationRoleAccess rules, including ancestor roles. This makes gallery visibility independent of stale location-role entries in the index. Missing encounters and nonmatching roles remain denied. Token searches retain their query-time indexed permission filtering.

Fixes #1779.

Validation

  • Added 11 regression tests covering missing/empty/stale indexed permissions, repeated requests, exact and ancestor roles, unrelated roles, current versus indexed locations, missing encounters, role revocation on the fallback path, token behavior, and existing indexed grants.
  • Five grant-side regression cases failed against the original code. All 78 targeted tests passed with the fix, with no failures, errors, or skips.
  • Ran mvn -o test -Dtest=SearchLocationRoleAccessTest,OpenSearchSanitizeDocTest,OpenSearchAclFilterTest,OpenSearchAclFilterIndexAwareTest,LocationRoleAccessTest,LocationRoleEncounterAccessTest,LocationRoleViewUsersTest,LocationRolePermissionsPassTest,LocationIDLineageTest.
  • Production acceptance check: use a non-admin researcher with the relevant Saimaa roles, open the galleries for Virpi and Teemu, and confirm stable permitted image counts across refreshes.

Implementation and review

Implemented and tested by OpenAI Codex. Claude independently reviewed a snapshot of the patch and relevant code and reported no blocking findings. Claude did not run the tests or reproduce the issue in production. Its review noted additional database lookups for denied browser-search hits, which may affect broad searches; this PR keeps the fallback limited to hits that indexed permissions deny. An outdated overload comment identified in review was corrected.

This change addresses the browser gallery’s location-role fallback. It does not eliminate background indexing lag or change token-search, collaboration, or organization-grant behavior. Database role-query errors remain request errors rather than silently returning an incomplete gallery.

No UI strings or dependencies changed.

Add a location-role fallback when indexed encounter permissions lag, using the current database location. Cover stale permissions and denied access with regression tests.

Implemented by OpenAI Codex; independently reviewed by Claude.
@JasonWildMe
JasonWildMe marked this pull request as draft September 30, 2026 19:57
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 54.89%. Comparing base (51faa7b) to head (89c158b).

Additional details and impacted files
@@           Coverage Diff            @@
##             main    #1780    +/-   ##
========================================
  Coverage   54.89%   54.89%            
========================================
  Files         314      314            
  Lines       12717    12717            
  Branches     4122     4013   -109     
========================================
  Hits         6981     6981            
  Misses       5441     5441            
  Partials      295      295            
Flag Coverage Δ
backend 54.89% <ø> (ø)
frontend 54.89% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@JasonWildMe JasonWildMe closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Seal Wildbook - Individual Gallery view displays different number of images at each refresh

2 participants