Skip to content

History user filter is ignored by semantic and indexed channel-log results #400

Description

@Calmingstorm

Confirmed inconsistent user filter

Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2.

SessionManager.search_history(..., user_id=...) applies the author filter to raw messages but not hybrid/semantic or indexed channel-log results. The REST search endpoint accepts this filter, so a supposedly user-scoped search can return other participants' messages.

Sources: hybrid filtering, REST parameters, aggregate archive document.

Isolated reproduction

Call real search_history('needle', user_id='alice') with a fake semantic backend returning a Bob-authored hit. Repeat with the channel-log FTS backend. Both results return Bob's hit unchanged.

Independently reproduced three times with synthetic authors/content. This proves filter behavior, not an authorization bypass: the REST route is normally admin-only, and the native search tool does not expose user_id.

Acceptance criteria

  • Apply author filtering to every included source with sufficient provenance.
  • If an aggregate result cannot prove author membership, omit it for user-scoped requests or resolve it to properly attributed messages.
  • Preserve channel/reset/time filters and ranking semantics for unfiltered searches.
  • Test raw, semantic, session FTS and channel-log sources together.

Behavior change: unrelated-author results disappear from explicitly filtered searches. No source changes were made.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions