[API][Workbench] user can see other users' trash
#1 Updated by Radhika Chippada almost 5 years ago
Due to the update made @ https://dev.arvados.org/projects/arvados/repository/revisions/695a100d4bd3bf4f5534c7e489c118c2917bf35a/diff/services/api/app/controllers/arvados/v1/collections_controller.rb, the readable_by filter is no longer working with unscoped and a user can see other users' trash.
#5 Updated by Nico César almost 5 years ago
Radhika ... how can I test if the bug is present ?
I see that the test failed for it
I don't know if it is temporary or not. I'm re-running those tests and let's see tomorrow
#6 Updated by Radhika Chippada almost 5 years ago
Nico asked: Radhika ... how can I test if the bug is present ?
Nico, I am sorry. I forgot to send you the instructions (as promised) before merging the code into master.
To test: need to login as a non-admin user and visit the https://workbench.4xphq.arvadosapi.com/trash page. Now you will see trashed collections in this user's projects or any other shared collections. Before the fix, the page listed the same collections as when an admin user accesses this page.