<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search API doesnt enforce permissions on Document links in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100734#M29035</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;first of all thanks for reading my question!&lt;/P&gt;&lt;P&gt;When i create link to a document in share and want to get it in share it inherits permissions from an original document, but when i use search/nodes api it returns links to documents/folders regardless of permissions to original documents/folders so when users try to follow those links the get 403 error.&lt;/P&gt;&lt;P&gt;Can i add some condition to query so it woudnt return links to documents which user has no permission to see.&lt;/P&gt;&lt;P&gt;I will add pictures below:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_10.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/494i4ECCB06C8E11016C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_15.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/497i0F555764774B7ADF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_14.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/498i08A7C141BB4FE440/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_13.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/493i7C7F779F9B36DA1B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_11.png" style="width: 764px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/496i1C0D21D9A52B6387/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Mar 2020 18:14:42 GMT</pubDate>
    <dc:creator>mire323</dc:creator>
    <dc:date>2020-03-19T18:14:42Z</dc:date>
    <item>
      <title>Search API doesnt enforce permissions on Document links</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100734#M29035</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;first of all thanks for reading my question!&lt;/P&gt;&lt;P&gt;When i create link to a document in share and want to get it in share it inherits permissions from an original document, but when i use search/nodes api it returns links to documents/folders regardless of permissions to original documents/folders so when users try to follow those links the get 403 error.&lt;/P&gt;&lt;P&gt;Can i add some condition to query so it woudnt return links to documents which user has no permission to see.&lt;/P&gt;&lt;P&gt;I will add pictures below:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_10.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/494i4ECCB06C8E11016C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_15.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/497i0F555764774B7ADF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_14.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/498i08A7C141BB4FE440/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_13.png" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/493i7C7F779F9B36DA1B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_11.png" style="width: 764px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://connect.hyland.com/t5/image/serverpage/image-id/496i1C0D21D9A52B6387/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 18:14:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100734#M29035</guid>
      <dc:creator>mire323</dc:creator>
      <dc:date>2020-03-19T18:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Search API doesnt enforce permissions on Document links</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100735#M29036</link>
      <description>&lt;P&gt;You can exclude links by adding something like the following clause to your queries:&lt;/P&gt;
&lt;PRE&gt;-TYPE:"app:filelink"&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Mar 2020 08:48:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100735#M29036</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2020-03-20T08:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Search API doesnt enforce permissions on Document links</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100736#M29037</link>
      <description>&lt;P&gt;I want to get links, but only ones i have right to see.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2020 18:59:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100736#M29037</guid>
      <dc:creator>mire323</dc:creator>
      <dc:date>2020-04-19T18:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Search API doesnt enforce permissions on Document links</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100737#M29038</link>
      <description>&lt;P&gt;What Alfresco Share does in filtering the link objects is not part of the regular permission model handling. It is a convenience filtering specific to the Share document library UI. You could use other operations in Alfresco Share, e.g. search, and would be able to find / access the link.&lt;BR /&gt;This convenience handling is of course missing in the ReST API, which simply returns all elements you are allowed to see. From a permission model perspective, you are allowed to see the link, but not the target. So the API of course returns you the link and its details.&lt;/P&gt;
&lt;P&gt;This is all behaviour as designed and this issue is one of the known drawbacks of using link nodes via APIs which where not designed to apply any special logic to them.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 16:17:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100737#M29038</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2020-04-20T16:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Search API doesnt enforce permissions on Document links</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100738#M29039</link>
      <description>&lt;P&gt;Thank you soo much for explaining that in such great detail!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 12:41:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/search-api-doesnt-enforce-permissions-on-document-links/m-p/100738#M29039</guid>
      <dc:creator>mire323</dc:creator>
      <dc:date>2020-04-22T12:41:37Z</dc:date>
    </item>
  </channel>
</rss>

