AppFlowy-IO / AppFlowy-IO/AppFlowy-Web

[Bug] I detected a few high priority urgent bugs

Abierto
#445 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
TypeScript
Estrellas
326
Forks
167
Merge medio
17 h 6 min
PR fusionados (30 d)
72

Descripción

### Bug Description

I ran Appflowy through a scan on my app Apptruth and it detected several high priority urgent issues, including one like private pages nested under public pages can be exposed publically. (Another issue showed empty schedules queries crash the backend).

I took a screenshot of the first 2 issues.

I went and tested these 2 issues manually myself and they were confirmed to be not working as epxected.

There were 12 more (14 in total).

You can run the same check for yourself on apptruth.io

Image

### Steps to Reproduce

1. go to app
2. create private page under public page
3. private page is publically available without auth

### The AI fix prompt

In `get_workspace_public_view_pbs` in `frontend/rust-lib/flowy-folder/src/manager.rs`, change the child-view filter to exclude both `trash_ids` and `private_view_ids`. Audit any recursive child traversal or alternative public-view builders and apply the same rule there. Add tests for a public parent with a private child and a trashed child; assert neither child appears in the public response while the owner can still access the private child through private views.

### Expected Behavior

The code excludes private pages at the top level. But when it adds child pages beneath a public parent, it removes trashed pages only and does not remove private children.

Where it happens:
frontend/rust-lib/flowy-folder/src/manager.rs—`get_workspace_public_view_pbs` filters `private_view_ids` for top-level views, but its `child_views.retain` call checks only `trash_ids`; the method comment says public views should be filtered by trash and all private views.

### Browser and Version

google chrome

### AppFlowy Version(s)

latest version

### Screenshots

_No response_

### Logs and Console Output

_No response_

### Additional Context

_No response_

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.