Skip to content

fix: collection level permissions - #2506

Merged
TorstenDittmann merged 2 commits into
feat-database-indexingfrom
fix-database-collection-level-permissions
Dec 17, 2021
Merged

TorstenDittmann merged 2 commits into
feat-database-indexingfrom
fix-database-collection-level-permissions

Conversation

@TorstenDittmann

Copy link
Copy Markdown
Contributor

What does this PR do?

When using Document Level Permissions, we are supposed to ignore Collection Level Permissions and vice versa.

  • Getting the Collection document is now always skipping authorization
    • will not throw a 404 anymore, but a 401
  • fixed the returned sum on collection level permissions
  • Fixed permission level for list, create, update and delete documents

Since this was discovered while I was working on Realtime, this PR also includes collection/document level permission for Realtime events:

  • send the collection document as part of the event
  • use collection permission or document permissions depending on the configured level

Test Plan

  • extended tests for the Database
  • added realtime tests

Have you read the Contributing Guidelines on issues?

✅

@kodumbeats kodumbeats left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LTGM 👍🏻

@TorstenDittmann
TorstenDittmann merged commit 0e84545 into feat-database-indexing Dec 17, 2021
@TorstenDittmann
TorstenDittmann deleted the fix-database-collection-level-permissions branch December 17, 2021 10:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants