# HG changeset patch # User Alain Mazy # Date 1774245108 -3600 # Node ID e8bb9ecc44846ec6b2f315c30c1260c6f6d686c7 # Parent 331809444cec7e3d2eb3b229e7ab9e257ec07d92 tools/find: take ParentSeries+ParentStudy into account diff -r 331809444cec -r e8bb9ecc4484 NEWS --- a/NEWS Fri Mar 20 19:13:46 2026 +0100 +++ b/NEWS Mon Mar 23 06:51:48 2026 +0100 @@ -6,7 +6,7 @@ * Added support for /tools/bulk-modify and /tools/bulk-anonymize * Fix: in /tools/bulk-delete, a user was able to delete resources he does not have access to. - +* Fix: in /tools/find, "ParentSeries" and "ParentStudy" fields were ignored. 2025-11-20 - v 0.10.3 ===================== diff -r 331809444cec -r e8bb9ecc4484 Plugin/Plugin.cpp --- a/Plugin/Plugin.cpp Fri Mar 20 19:13:46 2026 +0100 +++ b/Plugin/Plugin.cpp Mon Mar 23 06:51:48 2026 +0100 @@ -1130,23 +1130,36 @@ if (!HasAccessToAllLabels(profile)) // no need to adjust anything if the user has access to all labels { - if (!GetStudyInstanceUIDFromQuery(studyInstanceUID, query)) - { - throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: unable to call tools/find at Series or Instance level when the user does not have access to ALL labels or when there is no StudyInstanceUID in the query."); - } - - // since this is a series/instance find, make sure the user has access to the parent study - std::vector studyOrthancIds; - GetStudyOrthancIdFromStudyInstanceUID(studyOrthancIds, studyInstanceUID); - - if (studyOrthancIds.size() != 1) - { - throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: when using tools/find at Series or Instance level, unable to get the orthanc ID of StudyInstanceUID specified in the query. Found " + boost::lexical_cast(studyOrthancIds.size()) + " orthanc studies with this StudyInstanceUID"); - } - bool granted = false; OrthancPlugins::IAuthorizationParser::AccessedResources accessedResources; - authorizationParser_->AddDicomStudy(accessedResources, studyInstanceUID); + + if (query.isMember("ParentStudy") && query["ParentStudy"].isString()) + { + authorizationParser_->AddOrthancResource(accessedResources, Orthanc::ResourceType_Study, query["ParentStudy"].asString()); + } + else if (query.isMember("ParentSeries") && query["ParentSeries"].isString()) + { + authorizationParser_->AddOrthancResource(accessedResources, Orthanc::ResourceType_Series, query["ParentSeries"].asString()); + } + else + { // try to get the StudyInstanceUID from the Query + + if (!GetStudyInstanceUIDFromQuery(studyInstanceUID, query)) + { + throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: unable to call tools/find at Series or Instance level when the user does not have access to ALL labels or when there is no StudyInstanceUID in the query."); + } + + // since this is a series/instance find, make sure the user has access to the parent study + std::vector studyOrthancIds; + GetStudyOrthancIdFromStudyInstanceUID(studyOrthancIds, studyInstanceUID); + + if (studyOrthancIds.size() != 1) + { + throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: when using tools/find at Series or Instance level, unable to get the orthanc ID of StudyInstanceUID specified in the query. Found " + boost::lexical_cast(studyOrthancIds.size()) + " orthanc studies with this StudyInstanceUID"); + } + + authorizationParser_->AddDicomStudy(accessedResources, studyInstanceUID); + } if (!HasAuthorizedLabelsForResource(granted, accessedResources, profile)) {