[Bug 42623] New: Add ability to restrict which libraries can be selected in a report runtime parameter
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Bug ID: 42623 Summary: Add ability to restrict which libraries can be selected in a report runtime parameter Initiative type: --- Sponsorship --- status: Product: Koha Version: Main Hardware: All OS: All Status: NEW Severity: enhancement Priority: P5 - low Component: Reports Assignee: koha-bugs@lists.koha-community.org Reporter: andrew@bywatersolutions.com QA Contact: testopia@bugs.koha-community.org CC: lisette@bywatersolutions.com Currently, if a report contains a runtime parameter for Library any user can select any library. This is at odds with work in BZ 16631 and BZ 42621 to allow restriction of data access by library & group. We would like to establish a way to denote in a report that a Library runtime parameter should either default to the user's library or allow selection of only libraries within that user's library group. This work should make sure to enforce these limits at the controller level as well so users cannot circumvent the limit by manually editing a report URL. -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Michelle Spinney <mspinney@clamsnet.org> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |mspinney@clamsnet.org -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |Needs Signoff -- You are receiving this mail because: You are the assignee for the bug. You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #1 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 200264 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=200264&action=edit Bug 42623: Limit report library runtime parameters based on LimitReportsBy This patch takes the report branch limits in the LimitReportsBy syspref and applies them to the runtime parameters in a library report Test plan: 1. Apply patch and restart_all 2. Create a report with a Library runtime parameter 3. Ensure LimitReportsBy is set to No restriction 4. Run the report, all libraries should show in the dropdown for the library runtime parameter 5. Set LimitReportsBy to Library 6. Run the report again, this time the parameter should be limited to your logged in branch 7. Set LimitReportsBy to Library group 8. Create a library group, add some branches to it including your logged in branch 9. Run the report, this time only the branches you added in your group should be visible 10. On the report screen, amend the URL to have a branchcode that is not in your library group (in the 'sql_params=') 11. You should see an error message when submitting the request that you are not authorised -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #2 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 200265 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=200265&action=edit Bug 42623: Add a unit test Patch from commit 8cf1253 -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |matt.blenkinsop@openfifth.c | |o.uk Assignee|koha-bugs@lists.koha-commun |matt.blenkinsop@openfifth.c |ity.org |o.uk -- You are receiving this mail because: You are the assignee for the bug. You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Depends on| |42621 Referenced Bugs: https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42621 [Bug 42621] Extend report limitations by library to use library groups -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Brendan Lawlor <blawlor@clamsnet.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Comma delimited| |CLAMS list of Sponsors| | Status|Needs Signoff |Signed Off Sponsorship status|--- |Sponsored -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Brendan Lawlor <blawlor@clamsnet.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #200264|0 |1 is obsolete| | Attachment #200265|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #3 from Brendan Lawlor <blawlor@clamsnet.org> --- Created attachment 200560 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=200560&action=edit Bug 42623: Limit report library runtime parameters based on LimitReportsBy This patch takes the report branch limits in the LimitReportsBy syspref and applies them to the runtime parameters in a library report Test plan: 1. Apply patch and restart_all 2. Create a report with a Library runtime parameter 3. Ensure LimitReportsBy is set to No restriction 4. Run the report, all libraries should show in the dropdown for the library runtime parameter 5. Set LimitReportsBy to Library 6. Run the report again, this time the parameter should be limited to your logged in branch 7. Set LimitReportsBy to Library group 8. Create a library group, add some branches to it including your logged in branch 9. Run the report, this time only the branches you added in your group should be visible 10. On the report screen, amend the URL to have a branchcode that is not in your library group (in the 'sql_params=') 11. You should see an error message when submitting the request that you are not authorised Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #4 from Brendan Lawlor <blawlor@clamsnet.org> --- Created attachment 200561 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=200561&action=edit Bug 42623: Add a unit test Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #5 from Brendan Lawlor <blawlor@clamsnet.org> --- Created attachment 200562 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=200562&action=edit Bug 42623: (QA follow-up) Tidy Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Brendan Lawlor <blawlor@clamsnet.org> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |blawlor@clamsnet.org --- Comment #6 from Brendan Lawlor <blawlor@clamsnet.org> --- This works as described and will be helpful to consortia to be able to limit access to data and also conserve system resource. Thanks for working on this Matt! Testing notes: 8. Create a library group, add some branches to it including your logged in branch For step 8, make sure to check the box to Limit report access by group If you have the system preference LimitReportsBy set to 'Library group' and you don't have any library groups set up with 'Limit report access by group' then you won't be able to select any library as a runtime parameter. Instead the runtime parameter dropdown will just list 'No results found'. At first I thought that might be a bug, but it makes sense that you need a library group for Limit report access by group in order to LimitReportsBy 'Library group' Just noting it's important for documenting in the manual, or maybe there could even be a note added to the system preference to make that clear to administrators. I added a patch for tidying perl misc/devel/tidy.pl reports/guided_reports.pl because the qa script complained about missing spaces in a couple conditionals and some = that it wanted to be aligned. -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Andrew Fuerste-Henry <andrew@bywatersolutions.com> changed: What |Removed |Added ---------------------------------------------------------------------------- QA Contact|testopia@bugs.koha-communit |andrew@bywatersolutions.com |y.org | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Andrew Fuerste-Henry <andrew@bywatersolutions.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|Signed Off |Patch doesn't apply -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|Patch doesn't apply |Signed Off -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #200560|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #200561|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #200562|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #7 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206266 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206266&action=edit Bug 42623: Limit report library runtime parameters based on LimitReportsBy This patch takes the report branch limits in the LimitReportsBy syspref and applies them to the runtime parameters in a library report Test plan: 1. Apply patch and restart_all 2. Create a report with a Library runtime parameter 3. Ensure LimitReportsBy is set to No restriction 4. Run the report, all libraries should show in the dropdown for the library runtime parameter 5. Set LimitReportsBy to Library 6. Run the report again, this time the parameter should be limited to your logged in branch 7. Set LimitReportsBy to Library group 8. Create a library group, add some branches to it including your logged in branch 9. Run the report, this time only the branches you added in your group should be visible 10. On the report screen, amend the URL to have a branchcode that is not in your library group (in the 'sql_params=') 11. You should see an error message when submitting the request that you are not authorised Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #8 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206267 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206267&action=edit Bug 42623: Add a unit test Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #9 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206268 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206268&action=edit Bug 42623: (QA follow-up) Tidy Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #10 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206269 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206269&action=edit Bug 42623: (QA follow-up) Resolve runtime parameter limits to branchcodes The library_group branch of _confirm_branch_param_allowed and the Library runtime parameter dropdown only looked at qualifying library groups. A report limited to a library that is not in any reports group therefore allowed any branch, while the saved reports list hid the report. Both now use library_group_limit_branchcodes from bug 42621 so an ungrouped library is enforced as a group of one. The dropdown filter is now only applied when the report has limits. A report with no limits previously produced an empty IN () clause and an empty Library dropdown in library group mode. Also fixes the top-level test plan in t/db_dependent/Koha/Reports.t, which was not incremented when the _confirm_branch_param_allowed subtest was added. Test plan: 1. Set LimitReportsBy to Library group, create a group containing Centerville and Fairfield with "Limit report access by group" ticked 2. Create a report with a <<Library|branches>> runtime parameter and no library limit. Run it: the dropdown lists all libraries 3. Limit the report to Fairview only. Run it: the dropdown lists Fairview only. Amend sql_params in the URL to Centerville: access is refused 4. Limit the report to Centerville. Run it: the dropdown lists Centerville and Fairfield 5. prove t/db_dependent/Koha/Reports.t Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Andrew Fuerste-Henry <andrew@bywatersolutions.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|Signed Off |Patch doesn't apply --- Comment #11 from Andrew Fuerste-Henry <andrew@bywatersolutions.com> --- This no longer applies for me, gives "sha1 information is lacking or useless (reports/guided_reports.pl)" -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|Patch doesn't apply |Signed Off -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #206266|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #206267|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #206268|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> changed: What |Removed |Added ---------------------------------------------------------------------------- Attachment #206269|0 |1 is obsolete| | -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #12 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206781 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206781&action=edit Bug 42623: Limit report library runtime parameters based on LimitReportsBy This patch takes the report branch limits in the LimitReportsBy syspref and applies them to the runtime parameters in a library report Test plan: 1. Apply patch and restart_all 2. Create a report with a Library runtime parameter 3. Ensure LimitReportsBy is set to No restriction 4. Run the report, all libraries should show in the dropdown for the library runtime parameter 5. Set LimitReportsBy to Library 6. Run the report again, this time the parameter should be limited to your logged in branch 7. Set LimitReportsBy to Library group 8. Create a library group, add some branches to it including your logged in branch 9. Run the report, this time only the branches you added in your group should be visible 10. On the report screen, amend the URL to have a branchcode that is not in your library group (in the 'sql_params=') 11. You should see an error message when submitting the request that you are not authorised Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #13 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206782 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206782&action=edit Bug 42623: Add a unit test Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #14 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206783 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206783&action=edit Bug 42623: (QA follow-up) Tidy Signed-off-by: Brendan Lawlor <blawlor@clamsnet.org> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #15 from Matt Blenkinsop <matt.blenkinsop@openfifth.co.uk> --- Created attachment 206784 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206784&action=edit Bug 42623: (QA follow-up) Resolve runtime parameter limits to branchcodes The library_group branch of _confirm_branch_param_allowed and the Library runtime parameter dropdown only looked at qualifying library groups. A report limited to a library that is not in any reports group therefore allowed any branch, while the saved reports list hid the report. Both now use library_group_limit_branchcodes from bug 42621 so an ungrouped library is enforced as a group of one. The dropdown filter is now only applied when the report has limits. A report with no limits previously produced an empty IN () clause and an empty Library dropdown in library group mode. Also fixes the top-level test plan in t/db_dependent/Koha/Reports.t, which was not incremented when the _confirm_branch_param_allowed subtest was added. Test plan: 1. Set LimitReportsBy to Library group, create a group containing Centerville and Fairfield with "Limit report access by group" ticked 2. Create a report with a <<Library|branches>> runtime parameter and no library limit. Run it: the dropdown lists all libraries 3. Limit the report to Fairview only. Run it: the dropdown lists Fairview only. Amend sql_params in the URL to Centerville: access is refused 4. Limit the report to Centerville. Run it: the dropdown lists Centerville and Fairfield 5. prove t/db_dependent/Koha/Reports.t Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 Andrew Fuerste-Henry <andrew@bywatersolutions.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|Signed Off |Failed QA --- Comment #16 from Andrew Fuerste-Henry <andrew@bywatersolutions.com> --- When LimitReportsBy is set to "library group" and a report does not have any library limitations, this allows any library to be selected. But when LimitReportsBy is set to "library" and a report does not have any library selected this only allows the logged-in library to be selected. It would make more sense to me to treat these consistently: - If LimitReportsBy is set to "no restriction," all libraries appear in the dropdown - If LimitReportsBy is set to "library," reports without restrictions show all libraries in the dropdown and reports with restrictions only show the libraries to which they are restricted - If LimitReportsBy is set to "library groups," reports without restrictions show all libraries in the dropdown and reports with restrictions only show the libraries to which they are restricted and any libraries in a reports group with those libraries But this removes the option to restrict a user to only getting data about their logged-in branch. Smaller issue: there's a test failure due to incorrect test count: Test Summary Report ------------------- /kohadevbox/koha/t/db_dependent/Koha/Reports.t (Wstat: 65280 (exited 255) Tests: 22 Failed: 1) Failed test: 22 Non-zero exit status: 255 Parse errors: Bad plan. You planned 21 tests but ran 22. Files=1, Tests=22, 2 wallclock secs ( 0.01 usr 0.01 sys + 1.64 cusr 0.30 csys = 1.96 CPU) Result: FAIL -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #17 from Andrew Fuerste-Henry <andrew@bywatersolutions.com> --- I've raised this question to the library sponsoring the enhancement. -- You are receiving this mail because: You are watching all bug changes.
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42623 --- Comment #18 from Brendan Lawlor <blawlor@clamsnet.org> --- (In reply to Andrew Fuerste-Henry from comment #16)
When LimitReportsBy is set to "library group" and a report does not have any library limitations, this allows any library to be selected.
But when LimitReportsBy is set to "library" and a report does not have any library selected this only allows the logged-in library to be selected.
It would make more sense to me to treat these consistently: - If LimitReportsBy is set to "no restriction," all libraries appear in the dropdown - If LimitReportsBy is set to "library," reports without restrictions show all libraries in the dropdown and reports with restrictions only show the libraries to which they are restricted - If LimitReportsBy is set to "library groups," reports without restrictions show all libraries in the dropdown and reports with restrictions only show the libraries to which they are restricted and any libraries in a reports group with those libraries
But this removes the option to restrict a user to only getting data about their logged-in branch.
This makes sense to me. If we are limiting reports by library groups, and a report is limited by a library that is in a group, then the user should be able to select from the libraries in the group. Mostly this would be used for libraries in our consortium that have branches, or all libraries on a certain island. We don't have to limit strictly to the logged in branch, but I could see that being useful for others. Maybe there could be an optional checkbox on the library restrictions page that you could check limit to logged in branch only so you could do either. This is not a blocker for us. Thank you! -- You are receiving this mail because: You are watching all bug changes.
participants (1)
-
bugzilla-daemon@bugs.koha-community.org