Skip to content

fix: assets permission issues #1926 - #1928

Merged
NGPixel merged 3 commits into
requarks:masterfrom
PruvoNet:#1926
Jun 7, 2020
Merged

NGPixel merged 3 commits into
requarks:masterfrom
PruvoNet:#1926

Conversation

@regevbr

@regevbr regevbr commented May 24, 2020

Copy link
Copy Markdown
Contributor

fix: #1926
Added permission filtering when listing assets and folders

@auto-assign
auto-assign Bot requested a review from NGPixel May 24, 2020 12:21
@regevbr

regevbr commented May 31, 2020

Copy link
Copy Markdown
Contributor Author

@NGPixel did you have a chance to look at this PR? I think this is an important fix...

@regevbr

regevbr commented Jun 6, 2020

Copy link
Copy Markdown
Contributor Author

@NGPixel sorry to bother, I'm sure you are very busy. I saw you made a new release which is aswome and I already upgraded to it. But in order for me to publicly expose parts of my wiki, I need that fix. I hope you can CR it before the next release.

Comment thread server/graph/resolvers/asset.js Outdated
const folderHierarchy = await WIKI.models.assetFolders.getHierarchy(args.folderId)
const folderPath = folderHierarchy.map(h => h.slug).join('/')
let results = await WIKI.models.assets.query().where(cond)
results = _.filter(results, r => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't reassign results here. Should be const results = ... then you return the _filter().map() as 1 chained statement.

Comment thread server/graph/resolvers/asset.js Outdated
return result
const parentHierarchy = await WIKI.models.assetFolders.getHierarchy(args.parentFolderId)
const parentPath = parentHierarchy.map(h => h.slug).join('/')
results = _.filter(results, r => {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same issue here. Don't reassign, return the result directly.

@regevbr

regevbr commented Jun 7, 2020

Copy link
Copy Markdown
Contributor Author

Thanks @NGPixel I fixed your comments.

@NGPixel
NGPixel merged commit a508a27 into requarks:master Jun 7, 2020
@regevbr
regevbr deleted the #1926 branch June 7, 2020 21:00
@regevbr

regevbr commented Jun 7, 2020

Copy link
Copy Markdown
Contributor Author

Thanks @NGPixel! Really an awesome project :-)

jionggyu pushed a commit to jionggyu/wiki-2.5.302-patch that referenced this pull request Jul 9, 2024
rainforwind pushed a commit to rainforwind/wikijs that referenced this pull request Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

assets permission issues

2 participants