Repository navigation
fix: restrict unpublished SharePoint Online pages to owners/editors (#3645) - #4437
Merged
Merged
Conversation
SharePoint Online does not update a page's ACLs when it is unpublished, so the connector kept granting view-only users access to draft/unpublished pages under DLS. Detect the published state from the page version (major.minor) and, for unpublished pages, only grant access to owners/editors: view-only members are excluded from both unique per-page role assignments and inherited site permissions. Also expose a `published` field on site page documents. Closes #3645
Jan-Kazlouski-elastic
marked this pull request as draft
September 3, 2026 15:24
Resolve NOTICE.txt conflict by taking main's version.
Jan-Kazlouski-elastic
requested review from
artem-shelkovnikov and
erikcurrin-elastic
September 14, 2026 08:21
Jan-Kazlouski-elastic
marked this pull request as ready for review
September 14, 2026 08:22
|
|
||
| try: | ||
| return int(minor) == 0 | ||
| except ValueError: |
Contributor
Author
There was a problem hiding this comment.
Good catch
I wanted it to be less restrictive initially, but after thinking about it more, changing this to False makes more sense. If we can't parse the version, we shouldn't assume the page is published. Same as with _grants_access.
An unparsable minor version in OData__UIVersionString is no evidence that a site page is published, so restrict its ACL to owners/editors instead of assuming the page is live. Missing or empty version strings still default to published, since an absent field would otherwise restrict every page on the site.
Jan-Kazlouski-elastic
enabled auto-merge (squash)
September 14, 2026 14:05
Contributor
Author
|
@erikcurrin-elastic Your comment is addressed. Could you please re-review? |
erikcurrin-elastic
approved these changes
Sep 14, 2026
This was referenced Sep 14, 2026
Merged
Jan-Kazlouski-elastic
added a commit
that referenced
this pull request
Sep 15, 2026
…tors (#3645) (#4437) (#4480) Backports the following commits to 9.4: - fix: restrict unpublished SharePoint Online pages to owners/editors (#3645) (#4437) --------- Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co> Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Jan-Kazlouski-elastic
added a commit
that referenced
this pull request
Sep 15, 2026
…tors (#3645) (#4437) (#4481) Backports the following commits to 9.5: - fix: restrict unpublished SharePoint Online pages to owners/editors (#3645) (#4437) --------- Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co> Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Merged
1 task
Jan-Kazlouski-elastic
added a commit
that referenced
this pull request
Sep 17, 2026
…itors (#3645) (#4437) (#4491) Backported from #4437 Backports the following commits to 8.19: - fix: restrict unpublished SharePoint Online pages to owners/editors (#3645) (#4437) ## Backport notes - The `8.19` branch uses the monolithic `connectors/sources/sharepoint_online.py` layout (not the `sharepoint/sharepoint_online/` package on `main`). Changes were manually adapted; behaviour matches #4437. ## Test plan - [ ] `pytest tests/sources/test_sharepoint_online.py`
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
With DLS enabled, unpublished SharePoint Online pages were still returned to users with view access. SharePoint does not update a page's ACLs when it is unpublished, so the connector kept the old view-only permissions on the indexed document.
This detects draft vs published state from the page version string and restricts
_allow_access_controlon unpublished pages to owners/editors only. Apublishedfield is also exposed onsite_pagedocuments.Closes #3645
Changes
OData__UIVersionString(major version = published, minor version = draft)require_edit_accessto_get_access_control_from_role_assignmentEDIT_ITEM_MASK/EDIT_ROLE_TYPESconstantspublishedfield onsite_pagedocumentsTesting
209 passedintest_sharepoint_online.py.Notes for reviewers
published=Truewhen version info is missing, to avoid over-restricting access.datasource.pyandtest_sharepoint_online.py. A test merge shows one mechanical conflict in_get_access_control_from_role_assignment(this PR addsrequire_edit_access, fix(sharepoint): add compact site-group DLS mode to reduce ACL memory #4396 addssite_id). Tests auto-merge. Resolution is to keep both optional parameters and pass both fromsite_pages.