Skip to content

Players can read the game master's private notes and background on any character page #732

Description

@rubenvdlinde

What happens

Any logged-in user who opens a character's detail page sees the game master's private notes and the character's background story. Both fields are meant for game masters only:

  • slNotesPrivate is described as "Game master notes NOT visible to players" (lib/Settings/larpinq_register.json:148-154).
  • background is described as "Character background story (visible to GMs only)" (lib/Settings/larpinq_register.json:82-88).

The character detail page renders both in plain view: background in the char-identity widget (src/manifest.json:603-616) and slNotesPrivate in the char-progress widget "Game state & notes" (src/manifest.json:660-678). Neither widget has a role check.

Why

The only thing standing between these fields and a player is "visible": false, and that flag only hides a column from generic list and index views. It does not stop anyone from reading the field. Nothing in the register restricts who may read a property: grep -rn '"authorization"' lib/Settings/ finds one schema-level block (on xpAward, create/update/delete only) and no property-level block anywhere.

The page is just the visible surface. The same fields come back from the OpenRegister objects API for the character, because the character schema has no authorization block at all (see #319 and #310).

OpenRegister already supports property-level read rules (PropertyRbacHandler, an authorization block on the property itself, with read and update group lists), so the fix can live in this repo.

Fix direction

  • Add a property-level authorization block to slNotesPrivate with read and update restricted to gamemasters (and admin).
  • Do the same for background, keeping read access for the owning player. The portal design (openspec/changes/portal-contribution/design.md) says "GM-only" means hidden from other players, not from the author.
  • Check the other GM fields on the same widget (notice, requirementOverrides) against the same rule.
  • Once the server strips the fields, the widgets can stay as they are: an absent field renders empty.

Live check

  1. As a non-admin user who is not in gamemasters, open any character that has slNotesPrivate and background filled in.
  2. Look at the "Identity" and "Game state & notes" widgets. Today both values are shown.
  3. Also call GET /index.php/apps/openregister/api/objects/larpinq/character/{id} as that user and check whether the two keys are in the response.

Matrix rows

chr-gm-notes, chr-secrets-plots, wld-share-with-players in openspec/parity/capabilities.json (merged in #730). Related: #319, #310, #451 (which redacts slNotesPrivate from the player PDF, but not from the page or the API).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingsecurityA user can read or write what they must nottriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions