AppFlowy-IO / AppFlowy-IO/AppFlowy-Web

[Bug] I detected a few high priority urgent bugs

未關閉
#445 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
TypeScript
星號
326
分支
167
平均合併
17 小時 6 分鐘
30 天內合併 PR
72

描述

### Bug Description

I ran Appflowy through a scan on my app Apptruth and it detected several high priority urgent issues, including one like private pages nested under public pages can be exposed publically. (Another issue showed empty schedules queries crash the backend).

I took a screenshot of the first 2 issues.

I went and tested these 2 issues manually myself and they were confirmed to be not working as epxected.

There were 12 more (14 in total).

You can run the same check for yourself on apptruth.io

Image

### Steps to Reproduce

1. go to app
2. create private page under public page
3. private page is publically available without auth

### The AI fix prompt

In `get_workspace_public_view_pbs` in `frontend/rust-lib/flowy-folder/src/manager.rs`, change the child-view filter to exclude both `trash_ids` and `private_view_ids`. Audit any recursive child traversal or alternative public-view builders and apply the same rule there. Add tests for a public parent with a private child and a trashed child; assert neither child appears in the public response while the owner can still access the private child through private views.

### Expected Behavior

The code excludes private pages at the top level. But when it adds child pages beneath a public parent, it removes trashed pages only and does not remove private children.

Where it happens:
frontend/rust-lib/flowy-folder/src/manager.rs—`get_workspace_public_view_pbs` filters `private_view_ids` for top-level views, but its `child_views.retain` call checks only `trash_ids`; the method comment says public views should be filtered by trash and all private views.

### Browser and Version

google chrome

### AppFlowy Version(s)

latest version

### Screenshots

_No response_

### Logs and Console Output

_No response_

### Additional Context

_No response_

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。