OHDSI / OHDSI/WebAPI

User with 'read restricted Atlas Users' role cannot open their own objects created before receiving this role

Open
#2,323 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

security
Dominant language
Java
Stars
151
Forks
183
Avg merge
14m
Merged PRs (30d)
2

Description

Expected behavior

The objects created by a user are available for this user in spite of their role

Actual behavior

With the role 'read restricted Atlas Users', the user is not able to open or edit the objects they created before receiving this role

Steps to reproduce behavior
  1. user1 has created some objects (cohorts, concept sets, analyses of different types...)
  2. Administrator excludes user1 from their role and includes user1 to the 'read restricted Atlas Users' role
  3. user1 tries opening the objects created on the step 1

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by reproducing the three listed role and object-ownership steps, then trace the authorization checks used when opening and editing those objects. Done means objects created before the role change remain available to their creator while the restricted role rules still apply to other users.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authorization, backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.