Skip to content

GH Issue #1445: Check wiki TOC target container perms before render - #8127

Open
labkey-adam wants to merge 5 commits into
developfrom
fb_wiki_toc_perms
Open

labkey-adam wants to merge 5 commits into
developfrom
fb_wiki_toc_perms

Conversation

@labkey-adam

@labkey-adam labkey-adam commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Rationale

Users need read permission in the target container. See this issue.

Changes

  • Standardize the "no permission" message we show when rendering wiki, wiki version, or wiki toc (i.e., "Please log in" vs. "No permission")
  • Ensure read permission at wiki TOC render time. Display standard message if not.
  • Adjust wiki and wiki TOC webpart rendering to not show "Print" or "New" menu options when user can't read
  • Fix our MockRequest.getQueryString() to return the query string from the ActionURL, instead of always returning null

@labkey-adam labkey-adam changed the title GitHub Issue #1445: Check wiki TOC target container perms before render GH Issue #1445: Check wiki TOC target container perms before render Oct 3, 2026

@labkey-bpatel labkey-bpatel left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Manual testing looks good. Just a couple of comments below.

JspView<VersionBean> me = HttpView.currentView();
VersionBean bean = me.getModelBean();
User user = getUser();
Container c = getContainer();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The unused Container import can be removed since this line was deleted and there are no other Container usages.

@Override
public @Nullable String getQueryString()
{
return null == _actionURL || _actionURL.getParameters().isEmpty() ? null : _actionURL.getQueryString();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like this makes sense, but does this intentionally change the previous behavior where getQueryString() always returned null? (the parent method returned this.queryString, which was never set)

policy.addRoleAssignment(SecurityManager.getGroup(Group.groupGuests), ReaderRole.class);
SecurityPolicyManager.savePolicyForTests(policy, getAdmin());
html = renderToc(User.guest);
assertTrue("Expected guest login prompt, html was: " + html, html.contains("Please log in to see this data."));

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this use WikiManager.get().getNoPermissionsMessage(..) like above, instead of the hard-coded text?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants