Description
On a public dashboard, a relationship's target entity is rendered as Restricted / Entity_undefined, even though the entity is correctly org-shared with the same organisation as the (correctly-visible) source entity, and neither object carries any marking. The same relationship displays correctly on the authenticated/logged-in dashboard.
Environment
- Saas CSM platform 7.260921.0
- Public dashboard tested: JamieTestPublicDash - created from custom dash board : JamieTestPublic
https://csm.octi.staging.filigran.io/dashboard/workspaces/dashboards/7ac0785e-d934-4c35-9c74-6aa155b1c889
https://csm.octi.staging.filigran.io/public/dashboard/jamietestpublicdash
Reproducible steps
As a non-admin user (JamieTest) who is a member of organization JamieC Incorporated, create two Threat Actor (Individual) entities: BadBoy and GoodBoy.
Both are auto-tagged with objectOrganization: [JamieC Incorporated] on creation (expected org-segregation behavior).
Create a relationship BadBoy - cooperates-with→ GoodBoy.
Confirmed via GraphQL: the relationship also inherits objectOrganization: [JamieC Incorporated], and objectMarking: [] (no markings at all, on either entity or the relationship).
Create a Custom Dashboard with a Relationships List widget, perspective = relationships, filter = Source entity = BadBoy.
On the authenticated dashboard, the widget correctly shows: BadBoy - Cooperates With→ GoodBoy, Marking: -.
Enable Public Dashboard sharing on this dashboard, with max-level markings set generously (TLP:AMBER, PAP:AMBER) so the marking gate cannot be the limiting factor (irrelevant anyway since neither object has any marking).
Open the generated public link in an unauthenticated/incognito browser session.
Expected output
The relationship row should render identically to the authenticated view: BadBoy - Cooperates With→ GoodBoy
Actual output
Additional information
Suspected root cause code-level search offered :
In publicDashboard-utils.ts, getWidgetArguments builds a synthetic user object used for every public-dashboard query:
const user = { ...platformUser, origin: { user_id: platformUser.id, referer: 'public-dashboard' }, capabilities: [accessKnowledgeCapability], allowed_marking: allowedMaxMarkings, // ACL - Markings // ACL - Authorized members // ACL - Authorized authorities };
The markings ACL is explicitly implemented (allowed_marking); the organization/authorized-members ACL is left as a bare comment with no implementation !!!
The synthetic user's org context appears to fall back to whatever is spread in from platformUser, unadjusted for the actual dashboard/relationship context.
Also see : OCTI2-2455
Description
On a public dashboard, a relationship's target entity is rendered as Restricted / Entity_undefined, even though the entity is correctly org-shared with the same organisation as the (correctly-visible) source entity, and neither object carries any marking. The same relationship displays correctly on the authenticated/logged-in dashboard.
Environment
https://csm.octi.staging.filigran.io/dashboard/workspaces/dashboards/7ac0785e-d934-4c35-9c74-6aa155b1c889
https://csm.octi.staging.filigran.io/public/dashboard/jamietestpublicdash
Reproducible steps
As a non-admin user (JamieTest) who is a member of organization JamieC Incorporated, create two Threat Actor (Individual) entities: BadBoy and GoodBoy.
Both are auto-tagged with objectOrganization: [JamieC Incorporated] on creation (expected org-segregation behavior).
Create a relationship BadBoy - cooperates-with→ GoodBoy.
Confirmed via GraphQL: the relationship also inherits objectOrganization: [JamieC Incorporated], and objectMarking: [] (no markings at all, on either entity or the relationship).
Create a Custom Dashboard with a Relationships List widget, perspective = relationships, filter = Source entity = BadBoy.
On the authenticated dashboard, the widget correctly shows: BadBoy - Cooperates With→ GoodBoy, Marking: -.
Enable Public Dashboard sharing on this dashboard, with max-level markings set generously (TLP:AMBER, PAP:AMBER) so the marking gate cannot be the limiting factor (irrelevant anyway since neither object has any marking).
Open the generated public link in an unauthenticated/incognito browser session.
Expected output
The relationship row should render identically to the authenticated view: BadBoy - Cooperates With→ GoodBoy
Actual output
Additional information
Suspected root cause code-level search offered :
In publicDashboard-utils.ts, getWidgetArguments builds a synthetic user object used for every public-dashboard query:
const user = { ...platformUser, origin: { user_id: platformUser.id, referer: 'public-dashboard' }, capabilities: [accessKnowledgeCapability], allowed_marking: allowedMaxMarkings, // ACL - Markings // ACL - Authorized members // ACL - Authorized authorities };The markings ACL is explicitly implemented (allowed_marking); the organization/authorized-members ACL is left as a bare comment with no implementation !!!
The synthetic user's org context appears to fall back to whatever is spread in from platformUser, unadjusted for the actual dashboard/relationship context.
Also see : OCTI2-2455