immich user unable to add or remove from album #4609

Closed
opened 2026-02-05 10:43:53 +03:00 by OVERLORD · 5 comments
Owner

Originally created by @fOO223Fr on GitHub (Oct 21, 2024).

The bug

Immich users:

  1. user1
  2. user2

user1 uploads photos to their immich account.
user1 creates two albums:

  1. wedding1
  2. wedding2
    shared both albums to user2 with edit permission.

wedding1 has below assets:

  1. photo1
  2. photo2

wedding2 has below assets:

  1. photo3
  2. photo2

now user2 is trying to add photo1 to wedding2.
expectation: photo1 will now be part of both wedding1 and wedding2
reality: photo1 stays in wedding1 and wrong message is displayed after trying to add photo1 to wedding2 "Asset was already part of the album"

The OS that Immich Server is running on

Debian 12 - lxc container

Version of Immich Server

v1.118.2

Version of Immich Mobile App

v1.118.1

Platform with the issue

  • Server
  • Web
  • Mobile

Your docker-compose.yml content

cat docker-compose.yml 
#
# WARNING: Make sure to use the docker-compose.yml of the current release:
#
# https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml
#
# The compose file on main may not be compatible with the latest release.
#

name: immich

services:
  immich-server:
    container_name: immich_server
    image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release}
    # extends:
    #   file: hwaccel.transcoding.yml
    #   service: cpu # set to one of [nvenc, quicksync, rkmpp, vaapi, vaapi-wsl] for accelerated transcoding
    volumes:
      # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file
      - ${UPLOAD_LOCATION}:/usr/src/app/upload
      - /etc/localtime:/etc/localtime:ro
    env_file:
      - .env
    ports:
      - 2283:2283
    depends_on:
      - redis
      - database
    restart: always
    healthcheck:
      disable: false

  immich-machine-learning:
    container_name: immich_machine_learning
    # For hardware acceleration, add one of -[armnn, cuda, openvino] to the image tag.
    # Example tag: ${IMMICH_VERSION:-release}-cuda
    image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release}
    # extends: # uncomment this section for hardware acceleration - see https://immich.app/docs/features/ml-hardware-acceleration
    #   file: hwaccel.ml.yml
    #   service: cpu # set to one of [armnn, cuda, openvino, openvino-wsl] for accelerated inference - use the `-wsl` version for WSL2 where applicable
    volumes:
      - model-cache:/cache
    env_file:
      - .env
    restart: always
    healthcheck:
      disable: false

  redis:
    container_name: immich_redis
    image: docker.io/redis:6.2-alpine@sha256:e3b17ba9479deec4b7d1eeec1548a253acc5374d68d3b27937fcfe4df8d18c7e
    healthcheck:
      test: redis-cli ping || exit 1
    restart: always

  database:
    container_name: immich_postgres
    image: docker.io/tensorchord/pgvecto-rs:pg14-v0.2.0@sha256:90724186f0a3517cf6914295b5ab410db9ce23190a2d9d0b9dd6463e3fa298f0
    environment:
      POSTGRES_PASSWORD: ${DB_PASSWORD}
      POSTGRES_USER: ${DB_USERNAME}
      POSTGRES_DB: ${DB_DATABASE_NAME}
      POSTGRES_INITDB_ARGS: '--data-checksums'
    volumes:
      # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file
      - ${DB_DATA_LOCATION}:/var/lib/postgresql/data
    healthcheck:
      test: pg_isready --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' || exit 1; Chksum="$$(psql --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' --tuples-only --no-align --command='SELECT COALESCE(SUM(checksum_failures), 0) FROM pg_stat_database')"; echo "checksum failure count is $$Chksum"; [ "$$Chksum" = '0' ] || exit 1
      interval: 5m
      start_interval: 30s
      start_period: 5m
    command: ["postgres", "-c", "shared_preload_libraries=vectors.so", "-c", 'search_path="$$user", public, vectors', "-c", "logging_collector=on", "-c", "max_wal_size=2GB", "-c", "shared_buffers=512MB", "-c", "wal_compression=on"]
    restart: always

volumes:
  model-cache:

Your .env content

cat .env 
# You can find documentation for all the supported env variables at https://immich.app/docs/install/environment-variables

# The location where your uploaded files are stored
UPLOAD_LOCATION=/mnt/immich
# The location where your database files are stored
DB_DATA_LOCATION=./postgres

# To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List
# TZ=Etc/UTC

# The Immich version to use. You can pin this to a specific version like "v1.71.0"
IMMICH_VERSION=v1.118.2

# Connection secret for postgres. You should change it to a random password
# Please use only the characters `A-Za-z0-9`, without special characters or spaces
DB_PASSWORD=faking
# The values below this line do not need to be changed
###################################################################################
DB_USERNAME=fake
DB_DATABASE_NAME=immich

Reproduction steps

already mentioned in description

Relevant log output

No response

Additional information

No response

Originally created by @fOO223Fr on GitHub (Oct 21, 2024). ### The bug Immich users: 1. user1 2. user2 user1 uploads photos to their immich account. user1 creates two albums: 1. wedding1 2. wedding2 shared both albums to user2 with edit permission. wedding1 has below assets: 1. photo1 2. photo2 wedding2 has below assets: 1. photo3 2. photo2 now user2 is trying to add photo1 to wedding2. expectation: photo1 will now be part of both wedding1 and wedding2 reality: photo1 stays in wedding1 and wrong message is displayed after trying to add photo1 to wedding2 "Asset was already part of the album" ### The OS that Immich Server is running on Debian 12 - lxc container ### Version of Immich Server v1.118.2 ### Version of Immich Mobile App v1.118.1 ### Platform with the issue - [ ] Server - [X] Web - [ ] Mobile ### Your docker-compose.yml content ```YAML cat docker-compose.yml # # WARNING: Make sure to use the docker-compose.yml of the current release: # # https://github.com/immich-app/immich/releases/latest/download/docker-compose.yml # # The compose file on main may not be compatible with the latest release. # name: immich services: immich-server: container_name: immich_server image: ghcr.io/immich-app/immich-server:${IMMICH_VERSION:-release} # extends: # file: hwaccel.transcoding.yml # service: cpu # set to one of [nvenc, quicksync, rkmpp, vaapi, vaapi-wsl] for accelerated transcoding volumes: # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file - ${UPLOAD_LOCATION}:/usr/src/app/upload - /etc/localtime:/etc/localtime:ro env_file: - .env ports: - 2283:2283 depends_on: - redis - database restart: always healthcheck: disable: false immich-machine-learning: container_name: immich_machine_learning # For hardware acceleration, add one of -[armnn, cuda, openvino] to the image tag. # Example tag: ${IMMICH_VERSION:-release}-cuda image: ghcr.io/immich-app/immich-machine-learning:${IMMICH_VERSION:-release} # extends: # uncomment this section for hardware acceleration - see https://immich.app/docs/features/ml-hardware-acceleration # file: hwaccel.ml.yml # service: cpu # set to one of [armnn, cuda, openvino, openvino-wsl] for accelerated inference - use the `-wsl` version for WSL2 where applicable volumes: - model-cache:/cache env_file: - .env restart: always healthcheck: disable: false redis: container_name: immich_redis image: docker.io/redis:6.2-alpine@sha256:e3b17ba9479deec4b7d1eeec1548a253acc5374d68d3b27937fcfe4df8d18c7e healthcheck: test: redis-cli ping || exit 1 restart: always database: container_name: immich_postgres image: docker.io/tensorchord/pgvecto-rs:pg14-v0.2.0@sha256:90724186f0a3517cf6914295b5ab410db9ce23190a2d9d0b9dd6463e3fa298f0 environment: POSTGRES_PASSWORD: ${DB_PASSWORD} POSTGRES_USER: ${DB_USERNAME} POSTGRES_DB: ${DB_DATABASE_NAME} POSTGRES_INITDB_ARGS: '--data-checksums' volumes: # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file - ${DB_DATA_LOCATION}:/var/lib/postgresql/data healthcheck: test: pg_isready --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' || exit 1; Chksum="$$(psql --dbname='${DB_DATABASE_NAME}' --username='${DB_USERNAME}' --tuples-only --no-align --command='SELECT COALESCE(SUM(checksum_failures), 0) FROM pg_stat_database')"; echo "checksum failure count is $$Chksum"; [ "$$Chksum" = '0' ] || exit 1 interval: 5m start_interval: 30s start_period: 5m command: ["postgres", "-c", "shared_preload_libraries=vectors.so", "-c", 'search_path="$$user", public, vectors', "-c", "logging_collector=on", "-c", "max_wal_size=2GB", "-c", "shared_buffers=512MB", "-c", "wal_compression=on"] restart: always volumes: model-cache: ``` ### Your .env content ```Shell cat .env # You can find documentation for all the supported env variables at https://immich.app/docs/install/environment-variables # The location where your uploaded files are stored UPLOAD_LOCATION=/mnt/immich # The location where your database files are stored DB_DATA_LOCATION=./postgres # To set a timezone, uncomment the next line and change Etc/UTC to a TZ identifier from this list: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List # TZ=Etc/UTC # The Immich version to use. You can pin this to a specific version like "v1.71.0" IMMICH_VERSION=v1.118.2 # Connection secret for postgres. You should change it to a random password # Please use only the characters `A-Za-z0-9`, without special characters or spaces DB_PASSWORD=faking # The values below this line do not need to be changed ################################################################################### DB_USERNAME=fake DB_DATABASE_NAME=immich ``` ### Reproduction steps already mentioned in description ### Relevant log output _No response_ ### Additional information _No response_
Author
Owner

@alextran1502 commented on GitHub (Oct 21, 2024):

I assume photo1 is belong to user1, not user2, correct?

@alextran1502 commented on GitHub (Oct 21, 2024): I assume photo1 is belong to user1, not user2, correct?
Author
Owner

@fOO223Fr commented on GitHub (Oct 22, 2024):

@alextran1502 correct. all the photos belong to user1

@fOO223Fr commented on GitHub (Oct 22, 2024): @alextran1502 correct. all the photos belong to user1
Author
Owner

@unamdev0 commented on GitHub (Oct 27, 2024):

Hi @alextran1502 , I looked into this issue and it's because while adding an already existing pic to an album,we're checking if that asset has been shared with other user or not here.
a70ed7c7f6/server/src/utils/asset.util.ts (L36-L40)

Since user has permission to add new images to album but not existing image of other user, it throws no permission error

If this needs to be resolved, it can be done in two ways

  1. Make user as partner with the creator of album ( this seems wrong, as it'll give access to all the images rather than some particular images)

  2. Remove this permission check which is inside add asset function ( if we want user to be able to add images which are not actually shared with him)

Let me know if this is something that needs to be fixed, or if it's working as intended. If this needs to be fixed, please let me know which approach to follow

@unamdev0 commented on GitHub (Oct 27, 2024): Hi @alextran1502 , I looked into this issue and it's because while adding an already existing pic to an album,we're checking if that asset has been shared with other `user` or not here. https://github.com/immich-app/immich/blob/a70ed7c7f6962c4b2428d38ce79f0ac8a20ebde0/server/src/utils/asset.util.ts#L36-L40 Since user has permission to add new images to album but not existing image of other user, it throws no permission error If this needs to be resolved, it can be done in two ways 1. Make user as partner with the creator of album ( this seems wrong, as it'll give access to all the images rather than some particular images) 2. Remove this permission check which is inside add asset function ( if we want user to be able to add images which are not actually `shared` with him) Let me know if this is something that needs to be fixed, or if it's working as intended. If this needs to be fixed, please let me know which approach to follow
Author
Owner

@alextran1502 commented on GitHub (Oct 27, 2024):

@unamdev0 This is currently working as intended, as we are not allowing adding assets owned by different users to a different shared album, albeit the albums are shared among the users. We plan to rework the entire sharing permission and allow use cases like these

@alextran1502 commented on GitHub (Oct 27, 2024): @unamdev0 This is currently working as intended, as we are not allowing adding assets owned by different users to a different shared album, albeit the albums are shared among the users. We plan to rework the entire sharing permission and allow use cases like these
Author
Owner

@unamdev0 commented on GitHub (Oct 27, 2024):

got it, thanks

@unamdev0 commented on GitHub (Oct 27, 2024): got it, thanks
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: immich-app/immich#4609