enhancement
major
minor
major
minor
minor
#29673
TL Views: personalization commands ("Layout bearbeiten", "Diesen Filter speichern") are offered to the anonymous session
Problem
With no one logged in, a <dashboard> offers "Layout bearbeiten" and every <table> with a filter bar offers "Diesen Filter speichern" (TL Development app, "Meine Arbeit" and the ticket lists, snapshot build 42). All anonymous visitors share one anonymous account, so personal settings stored from that session would either be lost or be shared by every visitor.
Analysis: nothing in the persistence path checks for the anonymous account. Every personal setting (table state and saved filters, dashboard tile order, split sizes, sidebar state, dialog sizes, ...) goes into the session's TransientPersonalConfiguration, which TLContext.storePersonalConfiguration() writes back to the account's stored configuration - explicitly (dashboard reorder, start page, theme) and at the end of every sub-session for all other values. Changes made by an anonymous visitor therefore are persisted on the shared anonymous account and show up for every other visitor.
Expected
Commands that write personal settings (layout editing, saving a filter, and resetting or changing column widths or order, if they persist) are neither offered to nor executed for the anonymous session. Changes an anonymous visitor makes to a table stay in their session and are never persisted.
Lösung
- TLContext.storePersonalConfiguration() (and TransientPersonalConfiguration.storeConfiguration()) never write the personal configuration of the anonymous account. The in-memory configuration is kept for the rest of the session, so column widths, sorting, split sizes etc. keep working for the visitor but never reach the shared account; the next anonymous visitor starts with the defaults. This applies to all UIs (view layer and classic layouts). Settings already stored on the anonymous account stay readable.
- <dashboard>: the anonymous session gets no "Layout bearbeiten" command and no tile reordering.
- <table>: the anonymous session gets no store for named filters, so "Diesen Filter speichern" (and deleting a saved filter) is not offered; the filter bar itself stays.
- Demo (tl-demo-react): the login page links to a page a visitor may browse without an account ("Anonym stöbern", browse.view.xml, an anonymous entry point) with a dashboard of key figures and a filter-bar table of the chart demo's sales and purchases. The anonymous account reads these objects through the role demo.react.ChartReader, which a role rule assigns to the anonymous account's representative group only.