Skip to content

fix(dashboards): Public dashboards render org-shared relationship targets as "Restricted" (Entity_undefined) despite matching organization access #18469

Description

@fruitcakej

Description

On a public dashboard, a relationship's target entity is rendered as Restricted / Entity_undefined, even though the entity is correctly org-shared with the same organisation as the (correctly-visible) source entity, and neither object carries any marking. The same relationship displays correctly on the authenticated/logged-in dashboard.

Environment

  1. Saas CSM platform 7.260921.0
  2. Public dashboard tested: JamieTestPublicDash - created from custom dash board : JamieTestPublic

https://csm.octi.staging.filigran.io/dashboard/workspaces/dashboards/7ac0785e-d934-4c35-9c74-6aa155b1c889
https://csm.octi.staging.filigran.io/public/dashboard/jamietestpublicdash

Reproducible steps

As a non-admin user (JamieTest) who is a member of organization JamieC Incorporated, create two Threat Actor (Individual) entities: BadBoy and GoodBoy.

Both are auto-tagged with objectOrganization: [JamieC Incorporated] on creation (expected org-segregation behavior).
Create a relationship BadBoy - cooperates-with→ GoodBoy.
Confirmed via GraphQL: the relationship also inherits objectOrganization: [JamieC Incorporated], and objectMarking: [] (no markings at all, on either entity or the relationship).
Create a Custom Dashboard with a Relationships List widget, perspective = relationships, filter = Source entity = BadBoy.
On the authenticated dashboard, the widget correctly shows: BadBoy - Cooperates With→ GoodBoy, Marking: -.

Enable Public Dashboard sharing on this dashboard, with max-level markings set generously (TLP:AMBER, PAP:AMBER) so the marking gate cannot be the limiting factor (irrelevant anyway since neither object has any marking).
Open the generated public link in an unauthenticated/incognito browser session.

Expected output

The relationship row should render identically to the authenticated view: BadBoy - Cooperates With→ GoodBoy

Actual output

Additional information

Suspected root cause code-level search offered :

In publicDashboard-utils.ts, getWidgetArguments builds a synthetic user object used for every public-dashboard query:

const user = { ...platformUser, origin: { user_id: platformUser.id, referer: 'public-dashboard' }, capabilities: [accessKnowledgeCapability], allowed_marking: allowedMaxMarkings, // ACL - Markings // ACL - Authorized members // ACL - Authorized authorities };

The markings ACL is explicitly implemented (allowed_marking); the organization/authorized-members ACL is left as a bare comment with no implementation !!!
The synthetic user's org context appears to fall back to whatever is spread in from platformUser, unadjusted for the actual dashboard/relationship context.

Image

Also see : OCTI2-2455

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugType: something isn't working (fix:).needs triageNeeds triage from the Filigran product team.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions