What happens
Any logged-in user who opens a character's detail page sees the game master's private notes and the character's background story. Both fields are meant for game masters only:
slNotesPrivate is described as "Game master notes NOT visible to players" (lib/Settings/larpinq_register.json:148-154).
background is described as "Character background story (visible to GMs only)" (lib/Settings/larpinq_register.json:82-88).
The character detail page renders both in plain view: background in the char-identity widget (src/manifest.json:603-616) and slNotesPrivate in the char-progress widget "Game state & notes" (src/manifest.json:660-678). Neither widget has a role check.
Why
The only thing standing between these fields and a player is "visible": false, and that flag only hides a column from generic list and index views. It does not stop anyone from reading the field. Nothing in the register restricts who may read a property: grep -rn '"authorization"' lib/Settings/ finds one schema-level block (on xpAward, create/update/delete only) and no property-level block anywhere.
The page is just the visible surface. The same fields come back from the OpenRegister objects API for the character, because the character schema has no authorization block at all (see #319 and #310).
OpenRegister already supports property-level read rules (PropertyRbacHandler, an authorization block on the property itself, with read and update group lists), so the fix can live in this repo.
Fix direction
- Add a property-level
authorization block to slNotesPrivate with read and update restricted to gamemasters (and admin).
- Do the same for
background, keeping read access for the owning player. The portal design (openspec/changes/portal-contribution/design.md) says "GM-only" means hidden from other players, not from the author.
- Check the other GM fields on the same widget (
notice, requirementOverrides) against the same rule.
- Once the server strips the fields, the widgets can stay as they are: an absent field renders empty.
Live check
- As a non-admin user who is not in
gamemasters, open any character that has slNotesPrivate and background filled in.
- Look at the "Identity" and "Game state & notes" widgets. Today both values are shown.
- Also call
GET /index.php/apps/openregister/api/objects/larpinq/character/{id} as that user and check whether the two keys are in the response.
Matrix rows
chr-gm-notes, chr-secrets-plots, wld-share-with-players in openspec/parity/capabilities.json (merged in #730). Related: #319, #310, #451 (which redacts slNotesPrivate from the player PDF, but not from the page or the API).
What happens
Any logged-in user who opens a character's detail page sees the game master's private notes and the character's background story. Both fields are meant for game masters only:
slNotesPrivateis described as "Game master notes NOT visible to players" (lib/Settings/larpinq_register.json:148-154).backgroundis described as "Character background story (visible to GMs only)" (lib/Settings/larpinq_register.json:82-88).The character detail page renders both in plain view:
backgroundin thechar-identitywidget (src/manifest.json:603-616) andslNotesPrivatein thechar-progresswidget "Game state & notes" (src/manifest.json:660-678). Neither widget has a role check.Why
The only thing standing between these fields and a player is
"visible": false, and that flag only hides a column from generic list and index views. It does not stop anyone from reading the field. Nothing in the register restricts who may read a property:grep -rn '"authorization"' lib/Settings/finds one schema-level block (onxpAward, create/update/delete only) and no property-level block anywhere.The page is just the visible surface. The same fields come back from the OpenRegister objects API for the character, because the character schema has no
authorizationblock at all (see #319 and #310).OpenRegister already supports property-level read rules (
PropertyRbacHandler, anauthorizationblock on the property itself, withreadandupdategroup lists), so the fix can live in this repo.Fix direction
authorizationblock toslNotesPrivatewithreadandupdaterestricted togamemasters(and admin).background, keeping read access for the owning player. The portal design (openspec/changes/portal-contribution/design.md) says "GM-only" means hidden from other players, not from the author.notice,requirementOverrides) against the same rule.Live check
gamemasters, open any character that hasslNotesPrivateandbackgroundfilled in.GET /index.php/apps/openregister/api/objects/larpinq/character/{id}as that user and check whether the two keys are in the response.Matrix rows
chr-gm-notes,chr-secrets-plots,wld-share-with-playersinopenspec/parity/capabilities.json(merged in #730). Related: #319, #310, #451 (which redactsslNotesPrivatefrom the player PDF, but not from the page or the API).