Pane Shares drill hides an existing public link — shows only "Create link" (revoke only reachable from the Shares view) #682

Closed
opened 2026-09-23 10:01:52 +00:00 by Cordy · 0 comments
Owner

Found by the #656 QA pass (v0.6.247, files; the same behaviour was seen on files-bao).

Matrix row: §4 Sharing — "Public link revoke/expiry | Revoke …" and "Person share via panel … without leaving the page".

Steps

  1. files: _qa/qa-note.md has one active public link (created 03:27Z, expires the next day). The row shows a Public chip, and GET /api/v1/shares lists kind: link for it.
  2. Reload the page, select qa-note → pane → Shares.

Expected: the Public link section lists the existing link (expiry, Copy, revoke), as the sidebar Shares view does.
Seen: the section shows only the empty Create link form (Expires / password / Create link). Nothing indicates a live link already exists, and there is no revoke control in the pane. Right after creating a link in the same page session, the pane does show "Share link · Copy", but only until the pane or the page is reloaded. The Shares sidebar view (My shares) correctly lists "Public link · expires … · Copy link · revoke".

Consequences:

  • An owner looking at the pane will believe the file is not public (the list chip says otherwise).
  • Clicking Create link again mints a second live link instead of managing the first. Combined with #680, which creates links unintentionally, this makes stray public links easy to create and hard to notice.

If the fragment key is deliberately unrecoverable after creation, the pane can still list the link's existence, expiry and revoke without the Copy.

Screenshot: 682-pane-hides-existing-link.jpg (qa-note shows the Public chip; the pane offers only Create link)

Found by the #656 QA pass (v0.6.247, files; the same behaviour was seen on files-bao). **Matrix row:** §4 Sharing — "Public link revoke/expiry | Revoke …" and "Person share via panel … without leaving the page". **Steps** 1. files: `_qa/qa-note.md` has one active public link (created 03:27Z, expires the next day). The row shows a **Public** chip, and `GET /api/v1/shares` lists `kind: link` for it. 2. Reload the page, select qa-note → pane → Shares. **Expected:** the Public link section lists the existing link (expiry, Copy, revoke), as the sidebar Shares view does. **Seen:** the section shows only the empty *Create link* form (Expires / password / Create link). Nothing indicates a live link already exists, and there is no revoke control in the pane. Right after creating a link in the same page session, the pane does show "Share link · Copy", but only until the pane or the page is reloaded. The Shares sidebar view (My shares) correctly lists "Public link · expires … · Copy link · revoke". Consequences: - An owner looking at the pane will believe the file is not public (the list chip says otherwise). - Clicking Create link again mints a *second* live link instead of managing the first. Combined with #680, which creates links unintentionally, this makes stray public links easy to create and hard to notice. If the fragment key is deliberately unrecoverable after creation, the pane can still list the link's existence, expiry and revoke without the Copy. **Screenshot:** `682-pane-hides-existing-link.jpg` (qa-note shows the Public chip; the pane offers only Create link)
Cordy closed this issue 2026-09-23 18:02:10 +00:00
Sign in to join this conversation.
No labels
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Cordy/Cairn#682
No description provided.