visibleCollectionIDs returns the set of collection IDs the current user can see in the given workspace. Returns nil if the user has "all" access (no filtering needed), or a non-nil slice for "specific" access. Unauthenticated users (fresh install) always get nil (all access), as do platform admins —
(r *http.Request, workspaceID string)
| 2014 | // handler, handleCreateItem's collection-visibility check, and every other |
| 2015 | // direct caller) still granting a bearer admin an unrestricted view. |
| 2016 | func (s *Server) visibleCollectionIDs(r *http.Request, workspaceID string) ([]string, error) { |
| 2017 | user := currentUser(r) |
| 2018 | if user == nil || (user.Role == "admin" && !isBearerAuth(r)) { |
| 2019 | return nil, nil // No filtering for admins (cookie session) or unauthenticated |
| 2020 | } |
| 2021 | return s.store.VisibleCollectionIDs(workspaceID, user.ID) |
| 2022 | } |
| 2023 | |
| 2024 | // requireCollectionFullyVisible checks that the collection is visible to the |
| 2025 | // requesting user under FULL-collection-access semantics (BUG-1920 — |
no test coverage detected