Liferay 7:通过JavaScript调用JSON Web Service获取用户有权限的所有文件
Got it, let's fix this issue for you. The problem with your current code is that the /dlfileentry/get-group-file-entries service uses the userId parameter to filter files uploaded by that user, not to check which files the user has permission to view. That's why you're only seeing files the user uploaded themselves.
Here are two reliable methods to get all files a user can access:
Method 1: Use /dlapp/get-file-entries (Folder-Specific)
This service automatically checks the current user's VIEW permissions for files in the specified folder. It's the recommended approach for Liferay 7.x and above since it's part of the modern DLApp API with built-in permission handling.
Liferay.Service( '/dlapp/get-file-entries', { groupId: gId, folderId: 0, // Use 0 for root folder start: 0, end: 300, sort: 'modifiedDate', // Optional: Sort by modified date orderByType: 'desc' // Optional: Descending order }, function(obj) { console.log('Accessible files:', obj); } );
Method 2: Use /dlapp/get-file-entries-recursively (Include Subfolders)
If you need to pull files from all subfolders under the root (or a specific folder), use this recursive variant. It will traverse all child folders and return every file the user has permission to view:
Liferay.Service( '/dlapp/get-file-entries-recursively', { groupId: gId, folderId: 0, // Root folder start: 0, end: 300 }, function(obj) { console.log('All accessible files (including subfolders):', obj); } );
Key Notes:
- Permission Handling: Both
dlappservices respect Liferay's permission system. They'll only return files where the user has at leastVIEWpermission. - Filtering Options: You can add extra parameters to narrow results, like
mimeTypes: ['image/png', 'application/pdf']to filter by file type, ormodifiedDateGT: '2024-01-01'to get files modified after a specific date. - User Context: If you're running this in a frontend context, the service uses the currently logged-in user's permissions automatically. If you need to check permissions for a different user, you'll need to run the service in that user's context (e.g., via impersonation or backend code with a
PermissionCheckerfor that user).
内容的提问来源于stack exchange,提问作者Roy

