Repository navigation
Answer the permission a user holds on each of the given elements - #267
Merged
Merged
Conversation
The existing /elements/authorized answers all-or-nothing: a single forbidden element denies the whole request. Resolving the permissions of several independent elements therefore took one call each. The new /elements/permission returns which of the given elements the user may access, leaving out the forbidden and the unknown ones. The user groups are resolved once for the whole batch instead of once per element. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Aug 27, 2026
ghazwarhili
reviewed
Sep 7, 2026
The endpoint returns elements, not a permission, which its name now reflects. Its operation and response descriptions are aligned with the explore-server endpoint fronting it, which described the same thing in other words. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
…into feat/batch-element-permissions
userGroupIds already names a resolved List<UUID> a few lines above - the very list the lambda passed here captures - while this parameter is the Supplier deferring that resolution. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
ghazwarhili
approved these changes
Sep 9, 2026
etiennehomer
requested changes
Sep 11, 2026
Signed-off-by: Florent MILLOT <florent.millot_externe@rte-france.com>
…rmissions Signed-off-by: Florent MILLOT <florent.millot_externe@rte-france.com>
etiennehomer
approved these changes
Sep 18, 2026
A client resolving what a user may do with several elements needs the permission of each of them, not the subset matching one access type: the endpoint now answers the strongest permission held on each element, the ones held none at all on and the unknown ones being left out. The user groups are still read once for the whole batch, which is what makes asking about many elements cheap. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Asking whether the user holds MANAGE, then WRITE, then READ read the same rows three times over, none of these calls sharing a persistence context. The rows are read once and folded with the comparison the directory already had, so that the case this endpoint exists for - a user holding nothing - costs a third of the queries. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Reading the rows once and folding them saved two thirds of the key lookups on a user holding no permission, but it took nineteen lines where five said the same thing, and it dragged a pre-existing comparison into a rename this endpoint had no business making. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Asking whether the user holds MANAGE, then WRITE, then READ, element by element, read the permission table once per level and per element, none of these calls sharing a persistence context. The rows that apply to the user are now read in a single query for the whole batch, and the strongest of each element is kept with the comparison the directory already had. The elements that share the directory their permission is read on are asked for once. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Two reads whatever the size of the batch: the elements, then the permissions that apply to the user among them. Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
|
etiennehomer
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



GET /v1/elements/permissions?ids=…answers the strongest permission the user holds on each element, a directory being read on itself and any other element on its parent directory. An element the user holds no permission at all on is left out, as is an element that does not exist.