visibleCollectionIDs returns the set of collection IDs the current user can see in the given workspace. Returns nil if the user has "all" access (no filtering needed), or a non-nil slice for "specific" access. Unauthenticated users (fresh install) always get nil (all access), as do platform admins —
(r *http.Request, workspaceID string)
| 2743 | // handler, handleCreateItem's collection-visibility check, and every other |
| 2744 | // direct caller) still granting a bearer admin an unrestricted view. |
| 2745 | func (s *Server) visibleCollectionIDs(r *http.Request, workspaceID string) ([]string, error) { |
| 2746 | user := currentUser(r) |
| 2747 | if user == nil || (user.Role == "admin" && !isBearerAuth(r)) { |
| 2748 | return nil, nil // No filtering for admins (cookie session) or unauthenticated |
| 2749 | } |
| 2750 | return s.store.VisibleCollectionIDs(workspaceID, user.ID) |
| 2751 | } |
| 2752 | |
| 2753 | // requireCollectionFullyVisible checks that the collection is visible to the |
| 2754 | // requesting user under FULL-collection-access semantics (BUG-1920 — |