Cmd-K / command palettes usually hit a lightweight search endpoint tuned for speed. That path often filters by workspace_id and maybe deleted_at IS NULL, then returns titles for fuzzy match. The main search page runs the full viewer ACL. The palette does not.
A contractor types "acme" and sees "Acme renewal — legal hold" in the palette. The main search shows nothing for them. The title already leaked.
Point the palette at the same filtered search the full page uses, or run the detail-page read check on each hit before you render the title. If a hit fails, drop it. Don't grey it out with the name still visible.
Quick test: as a limited viewer, confirm a private doc is absent from main search, then open the palette and type part of its title. If it appears, the palette skipped the check.
If you want that filter in one place instead of inside every quick-search path, Permit.io is one option we use for resource-level decisions (full disclosure, I work with Permit.io).
Top comments (0)