Contract for findItemsWithEdit search method#210
Conversation
abollini
left a comment
There was a problem hiding this comment.
Thanks it almost aligns with other search methods in the collection endpoint, just a small comment to restrict it to authenticated user
tdonohue
left a comment
There was a problem hiding this comment.
👍 Thanks @ybnd ! This looks good now.
(Regarding the other similar methods, I'd anticipate they likely also should require authentication. So, that would sound like a bug to me, unless there's a documented reason why they are public endpoints. It's likely not a real security issue, since they should always return no permissions for anonymous users, but it does sound like a bug.)
abollini
left a comment
There was a problem hiding this comment.
thanks @ybnd my feedback as been addressed.
@tdonohue the discussion about the collection endpoint is of course out-of-scope of this PR but I like to anticipate that imho it is not a bug. We have had a use case some year ago where an institution allow anonymous deposit, it may be not supported out-of-box right now but it could be valid. Of course in a such scenario the Institution should have a validation workflow inplace
|
Hi @ybnd, |
|
Hi @ybnd, |
This search method was added in DSpace/DSpace#8616 to support the edit Item modal.