changeset 315:e8bb9ecc4484

tools/find: take ParentSeries+ParentStudy into account
author Alain Mazy <am@orthanc.team>
date Mon, 23 Mar 2026 06:51:48 +0100
parents 331809444cec
children 7da892a8a7b2
files NEWS Plugin/Plugin.cpp
diffstat 2 files changed, 29 insertions(+), 16 deletions(-) [+]
line wrap: on
line diff
--- a/NEWS	Fri Mar 20 19:13:46 2026 +0100
+++ b/NEWS	Mon Mar 23 06:51:48 2026 +0100
@@ -6,7 +6,7 @@
 * Added support for /tools/bulk-modify and /tools/bulk-anonymize
 * Fix: in /tools/bulk-delete, a user was able to delete resources
   he does not have access to.
-
+* Fix: in /tools/find, "ParentSeries" and "ParentStudy" fields were ignored.
 
 2025-11-20 - v 0.10.3
 =====================
--- a/Plugin/Plugin.cpp	Fri Mar 20 19:13:46 2026 +0100
+++ b/Plugin/Plugin.cpp	Mon Mar 23 06:51:48 2026 +0100
@@ -1130,23 +1130,36 @@
 
           if (!HasAccessToAllLabels(profile)) // no need to adjust anything if the user has access to all labels
           {
-            if (!GetStudyInstanceUIDFromQuery(studyInstanceUID, query))
-            {
-              throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: unable to call tools/find at Series or Instance level when the user does not have access to ALL labels or when there is no StudyInstanceUID in the query.");
-            }
-
-            // since this is a series/instance find, make sure the user has access to the parent study
-            std::vector<std::string> studyOrthancIds;
-            GetStudyOrthancIdFromStudyInstanceUID(studyOrthancIds, studyInstanceUID);
-
-            if (studyOrthancIds.size() != 1)
-            {
-              throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: when using tools/find at Series or Instance level, unable to get the orthanc ID of StudyInstanceUID specified in the query. Found " + boost::lexical_cast<std::string>(studyOrthancIds.size()) + " orthanc studies with this StudyInstanceUID");          
-            }
-
             bool granted = false;
             OrthancPlugins::IAuthorizationParser::AccessedResources accessedResources;
-            authorizationParser_->AddDicomStudy(accessedResources, studyInstanceUID);
+
+            if (query.isMember("ParentStudy") && query["ParentStudy"].isString())
+            {
+              authorizationParser_->AddOrthancResource(accessedResources, Orthanc::ResourceType_Study, query["ParentStudy"].asString());
+            }
+            else if (query.isMember("ParentSeries") && query["ParentSeries"].isString())
+            {
+              authorizationParser_->AddOrthancResource(accessedResources, Orthanc::ResourceType_Series, query["ParentSeries"].asString());
+            }
+            else
+            { // try to get the StudyInstanceUID from the Query
+
+              if (!GetStudyInstanceUIDFromQuery(studyInstanceUID, query))
+              {
+                throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: unable to call tools/find at Series or Instance level when the user does not have access to ALL labels or when there is no StudyInstanceUID in the query.");
+              }
+
+              // since this is a series/instance find, make sure the user has access to the parent study
+              std::vector<std::string> studyOrthancIds;
+              GetStudyOrthancIdFromStudyInstanceUID(studyOrthancIds, studyInstanceUID);
+
+              if (studyOrthancIds.size() != 1)
+              {
+                throw Orthanc::OrthancException(Orthanc::ErrorCode_ForbiddenAccess, "Auth plugin: when using tools/find at Series or Instance level, unable to get the orthanc ID of StudyInstanceUID specified in the query. Found " + boost::lexical_cast<std::string>(studyOrthancIds.size()) + " orthanc studies with this StudyInstanceUID");          
+              }
+
+              authorizationParser_->AddDicomStudy(accessedResources, studyInstanceUID);
+            }
 
             if (!HasAuthorizedLabelsForResource(granted, accessedResources, profile))
             {