From e34ba5aecc8a05c6d75ff581935dbc311fefc3d1 Mon Sep 17 00:00:00 2001 From: pedrooot Date: Wed, 7 Oct 2026 17:45:49 +0200 Subject: [PATCH] perf(api): skip the scan id list for unlimited roles --- api/src/backend/api/v1/views.py | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/api/src/backend/api/v1/views.py b/api/src/backend/api/v1/views.py index 5121f2e844..17f58272e5 100644 --- a/api/src/backend/api/v1/views.py +++ b/api/src/backend/api/v1/views.py @@ -4128,8 +4128,15 @@ class FindingViewSet(PaginateByPkMixin, BaseRLSViewSet): tenant_id = request.tenant_id query_params = request.query_params user_roles = self.user_role - visible_scan_ids = list( - _scans_visible_to(user_roles, tenant_id).values_list("id", flat=True) + # Only the restricted path uses these, and an unlimited role would load + # every tenant scan id for nothing. Materialised rather than kept lazy so + # Postgres gets a literal IN list, as `latest_ids_per_provider` documents. + visible_scan_ids = ( + None + if user_roles.unlimited_visibility + else list( + _scans_visible_to(user_roles, tenant_id).values_list("id", flat=True) + ) ) queryset = ResourceScanSummary.objects.filter(tenant_id=tenant_id)