Repository navigation
feat(cot): keep out-of-scope people in a transmission chain, masked - #25
Draft
lbrunofidelis wants to merge 2 commits into
Draft
lbrunofidelis wants to merge 2 commits into
lbrunofidelis wants to merge 2 commits into
Conversation
The front end needs to tell a person whose name was withheld apart from one that genuinely has no name on file.
A geographic restriction dropped out-of-scope relationships and people from a chain, so a restricted user saw false isolated nodes and chain counts that differed from an unrestricted user. Build the chain from the full relationship and people set and mask the out-of-scope people with the relationship name masking helpers instead of dropping them. An explicit person filter still narrows the chains. This covers the live chain, snapshots and the chain count.
This was referenced Sep 24, 2026
lbrunofidelis
marked this pull request as draft
September 24, 2026 13:59
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Por que
Em Cadeias de transmissão, o usuário com restrição geográfica perdia as pessoas de fora da área dele. Um contato da área cujo caso de origem era de outro município aparecia como uma bolinha solta, e as cadeias ficavam menores e em outra quantidade do que as de um usuário sem restrição. O pedido é ver a cadeia inteira, sem os dados nominais de quem ele não pode ver, do mesmo jeito que a tela de relacionamentos já faz.
Causa
O montador de cadeias em
common/controllers/outbreak.jsaplicava a restrição geográfica aos relacionamentos e às pessoas antes de montar a cadeia. Quem estava fora do escopo era descartado, junto com as ligações, e a cadeia perdia a forma real.O que muda
common/models/relationship.js: a pessoa com nome retido passa a vir commasked: truejunto dos campos de nome anulados.common/controllers/outbreak.jsecommon/models/relationship.js: a cadeia passa a ser montada com todos os relacionamentos e pessoas, e quem está fora do escopo do usuário é mascarado em vez de descartado (firstName,middleName,lastNameenamenulos emasked: true), com os mesmos helpers que já mascaram os nomes nas listas de relacionamento. O resto dos dados da pessoa segue igual. Um filtro explícito por pessoa continua restringindo as cadeias como antes. Vale para a cadeia ao vivo, para os snapshots e para a contagem, que usam o mesmo montador.Como validar
masked: true.Validado
Mesma base, mesmo surto, cadeia ao vivo com contatos:
devteste2)devteste2)masked: true.masked: truenas duas pontas fora do escopo.outbreak.jssem achados.relationship.jssó tem olinebreak-styleque o arquivo inteiro já tem nadev(o arquivo usa CRLF e as linhas novas seguem o mesmo padrão).Fora do escopo
maskedemRelationship.maskPersonName. A mudança é a mesma nas duas branches; a que entrar por último precisa de um rebase simples.Why (English)
In the transmission chains screen, a user restricted to a geographic area lost every out-of-scope person, so an in-scope contact whose source case lived elsewhere showed up as an isolated node and the chains differed in number and size from an unrestricted user's. The request is to see the whole chain without the nominal data of people the user may not see, the same way the relationship screen already works.
Root cause
The chain builder in
common/controllers/outbreak.jsapplied the geographic restriction to relationships and people before building the chain, dropping out-of-scope people and their links.What changes
relationship.js: a person whose name was withheld carriesmasked: true.outbreak.jsandrelationship.js: chains are built from the full relationship and people set, and out-of-scope people are masked instead of dropped (firstName,middleName,lastNameandnamenull,masked: true) with the same helpers that mask the relationship lists. An explicit person filter still narrows the chains. This covers live chains, snapshots and the chain count.How to validate
As a restricted user, build the outbreak chains: out-of-scope people appear connected, with null names and
masked: true, and the number and sizes of chains match the admin's. The admin sees no change.Validated
On the same data the restricted user went from 4 chains (sizes 3, 3, 2, 2, 6 edges) to the admin's 7 chains (sizes 8, 5, 4, 4, 3, 2, 2, 21 edges) with 15 masked nodes and none carrying a name; the admin output is identical before and after. Snapshot, count, person filter and edge detail checks agree. eslint is clean apart from the file-wide CRLF
linebreak-stylefindings thatrelationship.jsalready has ondev.Out of scope
Out-of-scope people with no relationships stay hidden, since they belong to no chain. The relationship security pull request (#24) sets the same
maskedflag inRelationship.maskPersonName; whichever lands last needs a trivial rebase.