jgraph/drawio-nextcloud

User without write permission can draw for a short time.

TheQuinNiX opened this issue · 3 comments

If a whiteboard is shared with other users who miss write permissons for the file in Nextcloud, they are able to draw for a short period of time, until the drawings get removed. This is quite confusing and makes it unusable in schools.

Can you please provide more details.

Can they write just initially or all the time?
How the drawings are removed?

I got two Nextcloud (v 25.0.4) users. User one creates a new draw.io Whiteboard and shares it with user two. Default permission while creating a share is without write access, just reading. So user one is owning the file and has write permission.

If both users open up the Whiteboard file, user one can draw and user two can see it. All right, all normal so far.
But if user two is drawing something, user one can see the drawings as well. But drawing (of user two) disappears automatically after 5-10 seconds for user one. For user two, the drawing is still visable.

Would be great if user two (without write access) can just see everything, but not draw at all.

Thanks a lot for the detailed report.

The bug will be fixed in the next draw.io version (the one after v21.2.9)