Conversation
MMilosz
marked this pull request as ready for review
September 23, 2026 14:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
References
Description
When an admin impersonates another user, some upload requests were missing the
X-On-Behalf-Ofheader on several code paths.This PR ensures the impersonation header is set on every upload path, i.e.:
/mydspace-> starting a submission via drag-and-drop (fixes When impersonating an eperson, submissions cannot be start by uploading a file. #6255)The header is set via
this.uploadFilesOptions.impersonatingID = this.authService.getImpersonateID();, mirroring the existing approach insubmission-form.component.tsBefore

After

Instructions for Reviewers
How to Test
To Impersonate: Log in as admin, go to Access Control -> People -> Edit any submitter (user with submit permissions) -> press the Impersonate button.
To Replace a Bitstream: this requires REST API having
replace-bitstream.enabled = true(which is not present in sandbox.dspace.org)Test 1 (fixes #6255)
Test 2 & 3 - replacing a bitstream (in-progress submission & bitstream page)
Ensure your DSpace API has
replace-bitstream.enabled = true(not present in sandbox). This allows you to replace a bitstream through the item page or during submission. Test both paths (reference: #4368).Observe no errors on upload. In Network tab, confirm both
X-On-Behalf-Of,X-Xsrf-Tokenheaders are presentTest 4 - edit-item page
X-On-Behalf-Of,X-Xsrf-Tokenheaders are presentTest 5 - community/collection logo
X-On-Behalf-Of,X-Xsrf-Tokenheaders are presentChecklist
mainbranch of code (unless it is a backport or is fixing an issue specific to an older branch).npm run lintnpm run check-circ-deps)package.json), I've made sure their licenses align with the DSpace BSD License based on the Licensing of Contributions documentation.