Skip to content

Answer the permission a user holds on each of the given elements - #267

Merged
flomillot merged 17 commits into
mainfrom
feat/batch-element-permissions
Oct 7, 2026
Merged

flomillot merged 17 commits into
mainfrom
feat/batch-element-permissions

Conversation

@flomillot

@flomillot flomillot commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

GET /v1/elements/permissions?ids=… answers the strongest permission the user holds on each element, a directory being read on itself and any other element on its parent directory. An element the user holds no permission at all on is left out, as is an element that does not exist.

The existing /elements/authorized answers all-or-nothing: a single
forbidden element denies the whole request. Resolving the permissions of
several independent elements therefore took one call each.

The new /elements/permission returns which of the given elements the user
may access, leaving out the forbidden and the unknown ones. The user
groups are resolved once for the whole batch instead of once per element.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 13e381a2-b9d3-4930-bd2a-e4cfff075b1a


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread src/main/java/org/gridsuite/directory/server/DirectoryController.java Outdated
Comment thread src/main/java/org/gridsuite/directory/server/DirectoryController.java Outdated
Comment thread src/main/java/org/gridsuite/directory/server/DirectoryController.java Outdated
Comment thread src/main/java/org/gridsuite/directory/server/services/PermissionService.java Outdated
Comment thread src/main/java/org/gridsuite/directory/server/services/PermissionService.java Outdated
The endpoint returns elements, not a permission, which its name now reflects.
Its operation and response descriptions are aligned with the explore-server
endpoint fronting it, which described the same thing in other words.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
userGroupIds already names a resolved List<UUID> a few lines above - the very
list the lambda passed here captures - while this parameter is the Supplier
deferring that resolution.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Comment thread src/main/java/org/gridsuite/directory/server/services/PermissionService.java Outdated
Signed-off-by: Florent MILLOT <florent.millot_externe@rte-france.com>
…rmissions

Signed-off-by: Florent MILLOT <florent.millot_externe@rte-france.com>
A client resolving what a user may do with several elements needs the
permission of each of them, not the subset matching one access type: the
endpoint now answers the strongest permission held on each element, the
ones held none at all on and the unknown ones being left out.

The user groups are still read once for the whole batch, which is what
makes asking about many elements cheap.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
@flomillot flomillot changed the title Add an endpoint filtering the elements a user can access Answer the permission a user holds on each of the given elements Sep 24, 2026
Asking whether the user holds MANAGE, then WRITE, then READ read the same
rows three times over, none of these calls sharing a persistence context.
The rows are read once and folded with the comparison the directory already
had, so that the case this endpoint exists for - a user holding nothing -
costs a third of the queries.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Reading the rows once and folding them saved two thirds of the key lookups
on a user holding no permission, but it took nineteen lines where five said
the same thing, and it dragged a pre-existing comparison into a rename this
endpoint had no business making.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Asking whether the user holds MANAGE, then WRITE, then READ, element by
element, read the permission table once per level and per element, none of
these calls sharing a persistence context.

The rows that apply to the user are now read in a single query for the whole
batch, and the strongest of each element is kept with the comparison the
directory already had. The elements that share the directory their permission
is read on are asked for once.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Two reads whatever the size of the batch: the elements, then the permissions
that apply to the user among them.

Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
Signed-off-by: Florent MILLOT <75525996+flomillot@users.noreply.github.com>
@sonarqubecloud

Copy link
Copy Markdown

@flomillot
flomillot merged commit c20b36f into main Oct 7, 2026
5 checks passed
@flomillot
flomillot deleted the feat/batch-element-permissions branch October 7, 2026 08:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants