Replies: 1 comment 1 reply
|
That looks like a real bug, not a missing cover. The overview is emitting Hiding the cover from anonymous visitors is correct. For an authenticated owner/admin session it should still return the thumbnail. Workaround until a patch: do not password albums you need to recognize in the grid, or use a parent album without a password and protect the children another way (hidden + share link). That is a poor substitute. A fix is: in the album resource / overview DTO, use the padlock only when the current user cannot unlock the album. Owner and users with the unlock already in session should get |
Uh oh!
There was an error while loading. Please reload this page.
Lychee version
Lychee 7.8.3
Did you check the latest Lychee version?
Yes, I did
Which PHP version are you using?
PHP 8.5
Detailed description of the problem
When an album is password-protected, the album overview shows
img/password.svg(padlock icon) instead of the album cover thumbnail — also for the album owner while logged in as admin.Hiding the cover from anonymous visitors makes sense. But for the owner in an authenticated session there seems to be no reason to hide it, and it makes managing a gallery visually difficult: with several protected albums the overview is just a row of padlocks, so albums can no longer be recognised at a glance.
Setting a cover image explicitly does not change the behaviour.
Evidence from my instance
Single user install,
users.id = 1, all albums havebase_albums.owner_id = 1. Logged in as that user, hard-reloaded the page.albums.cover_idaccess_permissions.passwordSo the padlock correlates with the password, not with a missing cover.
Rendered markup for a protected album:
The nginx access log shows no request to
/uploads/thumb/...for these albums, so the thumbnail URL is never emitted by the API rather than being blocked client-side.Steps to reproduce the issue
Diagnostics [REQUIRED]
info
Hash: d6c3d28fff8f4d73—96826e69c13d2d15
4059 files and 15632 vendor files
info
Full directory permission check is disabled
error
APP_URL (https://galler*************rew.com) does not match the current url (http://galler*************rew.com).
This will break WebAuthn authentication.
error
APP_URL (https://galler*************rew.com) does not match the current url (http://galler*************rew.com).
This will prevent images from being properly displayed.
warning
Default timezone not properly set; you might experience strange results when importing photos without explicit EXIF timezone
info
Have you considered supporting Lychee? :)
Browser & System [REQUIRED]
Info
Lychee Version (release): 7.8.3
DB Version: 7.8.3
Docker: lycheeorg
composer install: --no-dev
APP_ENV: production
APP_DEBUG: false
APP_URL: set
APP_DIR: default
LOG_VIEWER_ENABLED: false
System: Linux
PHP Version: 8.5.9
PHP User agent: Lychee/6 (https://lycheeorg.dev/)
int size 64 bits 8
Timezone: UTC
Max uploaded file size: 100M
Max post size: 100M
Chunk size: 25.60 MB
Max execution time: 3600
MySQL Version: 10.11.19-MariaDB-ubu2204
exec() Available: yes
Imagick Available: 1
Imagick Enabled: yes
Imagick Version: 1809
GD Version: 2.3.3
Number of foreign key: 55 found.
Please confirm (incomplete submissions will not be addressed)
All reactions