Privelege to list & view unsafe posts - #714
Open
Hunternif wants to merge 5 commits into
Open
Conversation
Contributor
|
That's a good feature, but I wish it wasn't pinned to unsafe category and could be applied to any of them. On that note, an extra "hidden" category with these permissions applied to it would be better solution. |
Since search queries get cached, when a search performed by a privileged user is repeated by an unprivileged user, they will receive a listing that erroneously includes unsafe posts. The same is true the other way around, a tag search that is first performed by an anonymous user will cause any hidden posts for that query to not show up for the logged in user. This is because the initial search claims the cache key.
Collaborator
|
The post listing change leads to cache collisions, I submitted a PR with a fix explaining the issue. Hunternif#2 |
server: prevent cache key collision
Collaborator
|
Closes #430. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Use case: I want to show off the awesome szurubooru to my friend, but I don't want them to see my nsfw posts XD
This PR adds 2 privileges:
The
viewprivilege restricts viewing "unsafe" posts viapost_api. (But you can still see thumbnails.)The
listprivilege filters out any "unsafe" posts from your query, for all queries.Adds unit tests too.