mirror of
https://github.com/paperless-ngx/paperless-ngx.git
synced 2026-10-10 01:57:12 +00:00
permitted_document_ids judged a version by its own owner and grants, so a version whose owner had drifted from its root's was visible to the wrong people and hidden from the right ones. Callers patched this individually by mapping each document to its root first. The query itself was also slow on MariaDB: the guardian grants were a UNION cast to integers and tested with IN inside an OR with the owner checks, which MariaDB cannot materialize, so it re-scans the user's grants for every document. At 20k documents that took seconds for a user with a couple of hundred grants. permitted_object_ids now casts the row key to a string, as guardian stores object_pk, and tests it against a single uncorrelated UNION ALL of the user's and groups' grants. No integer cast is needed and the user's groups are matched with an IN subquery rather than a join through the membership table. Postgres and SQLite build the grant set once, and MariaDB probes guardian's unique indexes per row, which is cheap. A correlated EXISTS per grant also fixed MariaDB but was up to 3x slower than before on Postgres and SQLite. permitted_object_ids also takes an optional parent_field naming a self-referencing foreign key whose target authorizes the row, and permitted_document_ids passes root_document, so a version is visible exactly when its root is. The helper that mapped documents to their roots at the call sites is no longer needed, so the email, selection data, share link bundle, trash, bulk download and bulk edit checks use the id set directly. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>