Skip to content

Avoid calling QA, notify or correctiontypes endpoints for anonymous users on item pages - #5932

Open
alexklbuckley wants to merge 8 commits into
DSpace:mainfrom
alexklbuckley:dspace-401-item-page
Open

Avoid calling QA, notify or correctiontypes endpoints for anonymous users on item pages#5932
alexklbuckley wants to merge 8 commits into
DSpace:mainfrom
alexklbuckley:dspace-401-item-page

Conversation

@alexklbuckley

@alexklbuckley alexklbuckley commented Jul 3, 2026

Copy link
Copy Markdown

References

Add references/links to any related issues or PRs. These may include:

Description

We should avoid unnecessarily filling the browser console and backend logs with 401 responses from anonymous users triggering calls to restricted API endpoints.

Sponsored-by: Auckland University of Technology, New Zealand

Instructions for Reviewers

Please add a more detailed description of the changes made by your PR. At a minimum, providing a bulleted list of changes in your PR is helpful to reviewers.

List of changes in this PR:

  • Wrap authentication conditionals around the inclusion of Angular components on the simple and full item pages.
  • Include checking if the current user is logged in when calling the correctiontypes/search/findByItem API endpoint in the correctiontype-data.service.ts

Include guidance for how to test or review your PR. This may include: steps to reproduce a bug, screenshots or description of a new feature, or reasons behind specific changes.

To Reproduce the bug

Steps to reproduce the behavior:

  1. Go to demo.dspace.org and do not login
  2. Do a search
  3. Right click and open your browser's 'Inspect Element'
  4. Click on the 'Console' tab
  5. Back in DSpace, click on an item page
  6. Notice several 401 responses from API endpoints.
  7. Notice 401 responses written to the backend logs as well

Apply the PR

  1. Go to demo.dspace.org and do not login
  2. Do a search
  3. Right click and open your browser's 'Inspect Element'
  4. Click on the 'Console' tab
  5. Back in DSpace, click on an item page
  6. No 401 responses from API endpoints.
  7. No 401 responses written to the backend logs

Checklist

This checklist provides a reminder of what we are going to look for when reviewing your PR. You do not need to complete this checklist prior creating your PR (draft PRs are always welcome).
However, reviewers may request that you complete any actions in this list if you have not done so. If you are unsure about an item in the checklist, don't hesitate to ask. We're here to help!

  • My PR is created against the main branch of code (unless it is a backport or is fixing an issue specific to an older branch).
  • My PR is small in size (e.g. less than 1,000 lines of code, not including comments & specs/tests), or I have provided reasons as to why that's not possible.
  • My PR passes ESLint validation using npm run lint
  • My PR doesn't introduce circular dependencies (verified via npm run check-circ-deps)
  • My PR includes TypeDoc comments for all new (or modified) public methods and classes. It also includes TypeDoc for large or complex private methods.
  • My PR passes all specs/tests and includes new/updated specs or tests based on the Code Testing Guide.
  • My PR aligns with Accessibility guidelines if it makes changes to the user interface.
  • My PR uses i18n (internationalization) keys instead of hardcoded English text, to allow for translations.
  • My PR includes details on how to test it. I've provided clear instructions to reviewers on how to successfully test this fix or feature.
  • If my PR includes new libraries/dependencies (in package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation.
  • If my PR includes new features or configurations, I've provided basic technical documentation in the PR itself.
  • If my PR fixes an issue ticket, I've linked them together.

@lgeggleston lgeggleston added authentication: general general authentication issues code task error handling How errors are handled from REST API 1 APPROVAL pull request only requires a single approval to merge labels Jul 6, 2026
@lgeggleston lgeggleston moved this to 🙋 Needs Reviewers Assigned in DSpace 11.0 Release Jul 6, 2026
@lgeggleston lgeggleston added the port to dspace-10_x This PR needs to be ported to `dspace-10_x` branch for next bug-fix release label Jul 6, 2026
@lgeggleston

Copy link
Copy Markdown
Contributor

Hi @alexklbuckley, thank you for noting and submitting this fix!
Note, this is currently failing a few build tests that will need to be addressed - but looks like only linting errors, which can also be checked using npm run lint.

@tinsch

tinsch commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Dear @alexklbuckley thanks for the fix! We encountered the issue as well. Could you fix the linting errors, so we can do a review or test?

I also saw similar errors on https://demo.dspace.org/browse/dateissued?bbm.page=1&startsWith=2023 for the paths
/server/api/system/scripts/metadata-import
/server/api/system/scripts/metadata-export
I think they can be fixed in a similar manner as done here, but maybe those should be addressed in a different issue.

Update: I filed a different bug ticket for that #6055

alexklbuckley and others added 3 commits August 4, 2026 14:27
…sers on item pages

- This should reduce the number of 401 responses written to the console
  and backend logs.

Sponsored-by: Auckland University of Technology, New Zealand
Sponsored-by: Auckland University of Technology, New Zealand
@alexklbuckley

Copy link
Copy Markdown
Author

Thanks for your replies @lgeggleston and @tinsch . I've pushed a follow-up which fixes failing lint tests. I see there are some unit tests that need fixing also. I am checking with our partner library if it's alright for us to spend the time fixing those up. I'll be in touch once I hear back.

@lgeggleston lgeggleston moved this from 🙋 Needs Reviewers Assigned to 👀 Under Review in DSpace 11.0 Release Aug 4, 2026
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Hi @alexklbuckley,
Conflicts have been detected against the base branch.
Please resolve these conflicts as soon as you can. Thanks!

Sponsored-by: Auckland University of Technology, New Zealand
@alexklbuckley

Copy link
Copy Markdown
Author

Our partner library has approved us to work on this so I am working through fixing the unit tests

Sponsored-by: Auckland University of Technology, New Zealand
Sponsored-by: Auckland University of Technology, New Zealand
@tinsch

tinsch commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

@alexklbuckley thanks for working on this again! There are still two linting errors, just some sorting of imports I think.

Sponsored-by: Auckland University of Technology, New Zealand
@alexklbuckley

Copy link
Copy Markdown
Author

thanks @tinsch ! I think Ive got the lint errors resolved now.

I've been working through unit test fixes for src/app/item-page/full/full-item-page.component.spec.ts , do you happen to know what I need to do to fix up https://github.com/DSpace/dspace-angular/actions/runs/31074594056/job/92529716941?pr=5932#step:13:11250 ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1 APPROVAL pull request only requires a single approval to merge authentication: general general authentication issues code task error handling How errors are handled from REST API port to dspace-10_x This PR needs to be ported to `dspace-10_x` branch for next bug-fix release

Projects

Status: 👀 Under Review

Development

Successfully merging this pull request may close these issues.

401 responses on item page load for anonymous users

3 participants