[Bug]: Guest/User account types have ability to view/edit/delete collections for everyone #615

Closed
opened 2026-04-24 23:14:42 +02:00 by adam · 2 comments
Owner

Originally created by @endangered-maritime-walrus on GitHub (Aug 30, 2022).

Describe the issue

Both Guests and Users have the ability to view, but more importantly, edit/delete items and/or entire collections.

Ideally, there would be a way to make a collection completely private.

Steps to reproduce the issue

  1. Create Collection in Admin account
  2. Create User/Guest
  3. Log in as User/Guest
  4. Go to collections
  5. Reorder, delete book from collections, or delete entire collection

Audiobookshelf version

v2.1.4

How are you running audiobookshelf?

Docker

Originally created by @endangered-maritime-walrus on GitHub (Aug 30, 2022). ### Describe the issue Both Guests and Users have the ability to view, but more importantly, edit/delete items and/or entire collections. Ideally, there would be a way to make a collection completely private. ### Steps to reproduce the issue 1. Create Collection in Admin account 2. Create User/Guest 3. Log in as User/Guest 4. Go to collections 5. Reorder, delete book from collections, or delete entire collection ### Audiobookshelf version v2.1.4 ### How are you running audiobookshelf? Docker
adam added the bug label 2026-04-24 23:14:42 +02:00
adam closed this issue 2026-04-24 23:14:42 +02:00
Author
Owner

@advplyr commented on GitHub (Aug 30, 2022):

I completely missed this somehow. Originally collections were going to be per-user then we decided to add "playlists" in the future that will be per-user.
In this case I think collections should only be editable/deleted by admin users, but everyone on the server will be able to view collections.
Playlists will essentially be collections but private per-user.

@advplyr commented on GitHub (Aug 30, 2022): I completely missed this somehow. Originally collections were going to be per-user then we decided to add "playlists" in the future that will be per-user. In this case I think collections should only be editable/deleted by admin users, but everyone on the server will be able to view collections. Playlists will essentially be collections but private per-user.
Author
Owner

@advplyr commented on GitHub (Sep 5, 2022):

Fixed in v2.1.5

@advplyr commented on GitHub (Sep 5, 2022): Fixed in [v2.1.5](https://github.com/advplyr/audiobookshelf/releases/tag/v2.1.5)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/audiobookshelf#615