From 57ce8640cc165c11665582a41826e345e6f61353 Mon Sep 17 00:00:00 2001 From: Masaharu Hayashi Date: Mon, 28 Sep 2026 10:18:23 +0000 Subject: [PATCH] =?UTF-8?q?fix(tools):=20=E6=B8=AC=E5=AE=9A=E7=94=A8?= =?UTF-8?q?=E3=82=A4=E3=83=B3=E3=83=87=E3=83=83=E3=82=AF=E3=82=B9=E3=81=AB?= =?UTF-8?q?=E9=96=B2=E8=A6=A7=E3=83=BB=E6=8A=95=E7=A8=BF=E3=82=B0=E3=83=AB?= =?UTF-8?q?=E3=83=BC=E3=83=97=E3=81=AE=E6=97=A2=E5=AE=9A=E5=80=A4=E3=82=92?= =?UTF-8?q?=E5=85=A5=E3=82=8C=E3=82=8B?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit v2.1.0 からインデックスの閲覧判定はロールに加えてグループの一致も要る (check_groups)。グループに属さない利用者とゲストは "-89"(No Group)として 照合される。fixtures.py は browsing_group / contribute_group を空のまま インデックスを作っていたため、公開インデックスの公開アイテムでも 一般ユーザ・未ログインが遮断され、測定結果が遮断に化けていた。 画面からインデックスを作ったときと同じ既定値(全グループ + "-89")を 入れる。index ステップの時点では測定用グループがまだ無いことがあるので、 グループ作成後の index_acl ステップで入れ直す。 Co-Authored-By: Claude Opus 5.5 --- tools/api-inventory/scripts/fixtures.py | 37 ++++++++++++++++++++++--- 1 file changed, 33 insertions(+), 4 deletions(-) diff --git a/tools/api-inventory/scripts/fixtures.py b/tools/api-inventory/scripts/fixtures.py index 50c4ade365..036de08474 100644 --- a/tools/api-inventory/scripts/fixtures.py +++ b/tools/api-inventory/scripts/fixtures.py @@ -188,6 +188,19 @@ def _users(): # ---------------------------------------------------------------- インデックス +def _default_groups(): + """画面からインデックスを作ったときと同じ閲覧・投稿グループの既定値。 + + weko_index_tree.api.Indexes.get_account_group と同じく、全グループに + "-89"(No Group)を足したもの。v2.1.0 からインデックスの閲覧判定は + ロールに加えてグループの一致も要る(check_groups)。グループに属さない + 利用者とゲストは "-89" として照合されるので、これが無いと公開インデックスでも + 一般ユーザ・未ログインが遮断され、公開アイテムの測定結果が遮断に化ける。 + """ + from weko_groups.models import Group + return ",".join([str(g.id) for g in Group.query.all()] + ["-89"]) + + @step("index") def _index(): from weko_index_tree.models import Index @@ -213,6 +226,8 @@ def _index(): idx.parent = 0 idx.public_state = True idx.harvest_public_state = True + idx.browsing_group = _default_groups() + idx.contribute_group = _default_groups() db.session.add(idx) db.session.flush() OUT["index"] = int(idx.id) @@ -249,6 +264,8 @@ def _index(): c.index_name_english = en c.public_state = public c.harvest_public_state = public + c.browsing_group = _default_groups() + c.contribute_group = _default_groups() db.session.add(c) OUT["indexes"][en] = int(c.id) db.session.flush() @@ -678,9 +695,12 @@ def _index_acl(): * "-98" はロールを持たない認証済ユーザの扱い * 認証済ユーザは*自分の全ロールがリストに含まれる*必要がある(AND判定)。 "1,2" は System/Repository 管理者だけが通り、Contributor は通らない - * browsing_group は所属していれば通る + * ロールに加えて browsing_group の一致も要る。所属グループがあれば + そのどれかが、無ければ "-89"(No Group)が含まれていないと遮断される。 + ゲストも "-89" として照合される - group を使うのでグループ作成の後に置く。 + group を使うのでグループ作成の後に置く。index ステップの時点では + 測定用グループがまだ無いことがあるので、ここで既定のグループを入れ直す。 """ import datetime from weko_index_tree.models import Index @@ -691,6 +711,15 @@ def _index_acl(): gid = (OUT.get("group") or {}).get("id") future = datetime.datetime(2099, 1, 1) private_id = (OUT.get("indexes") or {}).get("Restricted") + groups = _default_groups() + + # index ステップで作ったインデックスにも、測定用グループを含めた既定値を入れ直す + for iid in [root] + list((OUT.get("indexes") or {}).values()): + base = Index.query.filter_by(id=iid).one_or_none() + if base is not None: + base.browsing_group = groups + base.contribute_group = groups + db.session.add(base) specs = [ (900016, "公開前資料", "Embargoed", root, @@ -733,8 +762,8 @@ def _index_acl(): idx.harvest_public_state = True idx.browsing_role = "3,-98,-99" idx.contribute_role = "1,2,3,4,-98,-99" - idx.browsing_group = None - idx.contribute_group = None + idx.browsing_group = groups + idx.contribute_group = groups idx.public_date = None for k, v in extra.items(): setattr(idx, k, v)