Security (aka Permissions) and Lucene - How ? Should it be done?

后端 未结 4 1982
你的背包
你的背包 2020-12-13 04:42

First some background to my question.

  • Individual entities can have read Permissions.
  • If a user fails a read permission check they cant see th
4条回答
  •  悲&欢浪女
    2020-12-13 05:30

    As Yuval mentioned, it might be worth having the permission mechanism independent of the lucene index.

    One way to do it is to implement your own Collector, that will filter out the results that the user should not have access to.

提交回复
热议问题