LibreSign / LibreSign/libresign

Documents not loadable with Secure View

Open
#5,248 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
PHP
Stars
818
Forks
146
Avg merge
11h 31m
Merged PRs (30d)
326

Description

Describe the bug

When collabora (richdocuments) app is used for viewing Office documents and PDFs on Nextcloud, if a user is part of a group affected by secure view, the Libre Signing document link will only load a blank page.

To reproduce
  • Make use of richdocuments/collabora for PDF viewing
  • Send a doc to sign to a user in a secure view group
  • View a blank page instead of the document for signing
Expected behavior

To see the document for signing

Screenshots

No response

Environment information
  • OS: Linux Debian
  • Browser Chrome or Edge
  • LibreSign Version: 11.2.5
  • Nextcloud Server Version: Nextcloud Hub 10
  • Collabora Version: Collabora Online Development Edition 25.04.4.1 5aa2ead294

-Logs:
ForbiddenException
Download blocked due the secure view policy

Additional context

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue with richdocuments/collabora, a PDF or Office document, and a user in a secure view group. Start with the reported ForbiddenException, then trace the document-signing load path; done means the signing document loads instead of showing a blank page while secure view remains enforced.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.