https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43262

            Bug ID: 43262
           Summary: Public biblio items API does not check OpacSuppression
   Initiative type: ---
        Sponsorship ---
            status:
           Product: Koha
           Version: Main
          Hardware: All
                OS: All
            Status: NEW
          Severity: major
          Priority: P5 - low
         Component: Architecture, internals, and plumbing
          Assignee: [email protected]
          Reporter: [email protected]
        QA Contact: [email protected]
        Depends on: 43258
  Target Milestone: ---

GET /api/v1/public/biblios/:id/items
(Koha::REST::V1::Biblios::get_items_public) does not check whether the parent
biblio is suppressed. If a client knows the biblio_id of a suppressed record,
they can enumerate its items via the public API.

The endpoint uses filter_by_visible_in_opac() which handles OpacHiddenItems at
the item level, but does not check biblio-level suppression (OpacSuppression /
OpacSuppressionByIPRange).

Impact: information disclosure - items belonging to suppressed bibliographic
records are accessible via the public API.

Affected endpoints:
- GET /api/v1/public/biblios/:id/items
(Koha::REST::V1::Biblios::get_items_public)

Related: bug 43258 introduces Koha::IP and Koha::REST::Plugin::Restrictions
which provide the fix mechanism.


Referenced Bugs:

https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43258
[Bug 43258] Add a centralized IP range matching helper
-- 
You are receiving this mail because:
You are the assignee for the bug.
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to