edocman tags filter modul - respect permissions of documents

  • ChrissMa
  • Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
2 weeks 3 days ago #177558 by ChrissMa
Hello!
Tags get attached to documents. Documents have specific access groups or / and owners.
Tags should only be shown in the tags filter module if the actual user has the right to view / download / manage the documents.
In other words: show only tags that are relevant to the specific user.

There would be several strategies:
* a tag inherits the access level of the user who created it.
* a tag inherits the access rights of the document.
* a tag has no access rights but the module's logic shows only tags from documents that the user has access to.
* ...

It does not make sense to have a list of tags in the dropdown but there are no documents to access. In fact it can be a issue if the tag name reveals some sensitive data (names, ids, etc.) Since tags can be named freely (which is good) this case happend on my site. A tag revealed a name to a user who had no right to see that information.

Regards!
Chris
 

Please Log in or Create an account to join the conversation.

More
2 weeks 2 days ago #177576 by Dang Thuc Dam
Hi Chriss,
You are correct—this is an existing issue. However, it is a minor bug.
Please submit a support ticket in the Edocman category, and we will send you the latest version of the Edocman tags module to address the problem you mentioned.

Thank you for your feedback!
Dam

Please Log in or Create an account to join the conversation.

Moderators: Dang Thuc Dam