Describe the bug
Anonymous users can tell whether an item has a draft version in progress (due to presence of Version History table, see screenshot above), even though the REST contract explicitly says they should not be able to:
Due to the restriction applied to this flag anonymous users will be unable to discover that a new version is currently under review.
Source: https://github.com/DSpace/RestContract/blob/main/versionhistories.md#linked-entities
Observed on sandbox.dspace.org.
To Reproduce
Ensure the REST API has versioning enabled (true on sandbox.dspace.org).
- Go to any Item that does not have any version. Observe that no Version History table is shown.
- Log in as admin, create a new version of the Item (do not deposit it).
- Open Item page in a new window (incognito mode). Note the Version History table is shown with a single record.
Expected behavior
Anonymous users should not be able to discover that a new version is under review.
The Version History table should be shown only if there are >= 2 published items (but that's only my opinion!)
Related work
Describe the bug
Anonymous users can tell whether an item has a draft version in progress (due to presence of Version History table, see screenshot above), even though the REST contract explicitly says they should not be able to:
Observed on sandbox.dspace.org.
To Reproduce
Ensure the REST API has versioning enabled (true on sandbox.dspace.org).
Expected behavior
Anonymous users should not be able to discover that a new version is under review.
The Version History table should be shown only if there are >= 2 published items (but that's only my opinion!)
Related work
dspace.customurlin search results #5281 (comment). As soon as the new version is created, still a draft, the custom URL rotation happens. The custom URL still redirects to this item, but hovering over URLs shows a UUID instead of a friendly URL slug