# project: Stop sharing private files through project search \(\#63860\) · gitcafe/zed

[View on GitCafe](https://git.cafe/gitcafe/zed/commit/10676bad1dc13cfebd4f9c63ac536fa1c232cabe)

Repository: [gitcafe/zed](https://git.cafe/gitcafe/zed)

Visibility: public

Requested revision: 10676bad1dc13cfebd4f9c63ac536fa1c232cabe

Requested commit: 10676bad1dc13cfebd4f9c63ac536fa1c232cabe

Commit: 10676bad1dc13cfebd4f9c63ac536fa1c232cabe

Tree: 870bc9aadb7388907e5b919801b884fb82b0a898

Author: Ali

Committer: GitHub

## Message

```
project: Stop sharing private files through project search (#63860)

# Objective

Files matching the `private_files` setting are meant not to be shared
with collaborators. That is true when a guest asks to open one directly,
`respond_to_open_buffer_request` refuses with `ErrorCode::UnsharedItem`.

Project search reaches the same `create_buffer_for_peer` without passing
through that check. In `handle_search_candidate_buffers`, every matching
buffer was shared with the requesting peer unconditionally, so a guest
searching for a string that happens to appear in a private file received
the buffer containing it.

## Solution

Check `is_private` before sharing a matched buffer with a peer

## Testing

added new test `test_project_search_excludes_private_files` in the
collab integration suite:"
The host configures `private_files: ["**/.env"]` and has two files
`.env` containing `API_KEY=secret` and `a.txt` containing `the secret is
out`. The guest joins the shared project and searches for `secret`.



---

Release Notes:
- Fixed private files being shared with collaborators through project
search.
```

## Parents

- [ff6a6abbd1788eeee2a76766ef5188ee5a046e61](https://git.cafe/gitcafe/zed/commit/ff6a6abbd1788eeee2a76766ef5188ee5a046e61?format=markdown)

[Source at this commit](https://git.cafe/gitcafe/zed/tree/10676bad1dc13cfebd4f9c63ac536fa1c232cabe?format=markdown)
