openlibhums / openlibhums/janeway
Correspondence Author not listed as Author, unable to view revision request
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 238
- Forks
- 97
- Avg merge
- 9d 1h
- Merged PRs (30d)
- 8
Description
Edit by Joe 8 on Jun 2026
Personally identifying info and screenshots moved to openlibhums/bau#393.
Describe the bug
MIJ's editors emailed us because an author was unable to view the revision request for his article: nothing was displaying on his dashboard, and when he clicked the link in the revision request email, he got a "Permission Denied" page.
Eventually we determined the problem: for some reason, despite being the Owner and Correspondence Author of the article/submission, this author's account was not present on the list of Authors.
After manually adding his account to the Authors list in Admin, his account was able to access the revision request, both via the link in the email and from his dashboard. So this specific instance has been resolved, but I think that there must have been some kind of bug that allowed it to happen in the first place.
Janeway version
1.7.4
Expected behavior
I'm not sure exactly how a user could be the Correspondence Author without being listed as an Author...but regardless, it seems like there's some kind of bug at play here. I would think that either (a) the Correspondence Author should have permission to view the revision request, regardless of the Authors list, or (b) it should be impossible for a user to be selected as Correspondence Author without first being included on the Authors list.
Screenshots
See openlibhums/bau#393.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files or tests are named. Start at the Admin author assignment and the revision-request dashboard and email-link permission paths, then reproduce a case where the Correspondence Author is absent from Authors. Done means one consistent behavior is established—access is granted or the selection is prevented—and the permission-denied case is covered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- authorization
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100