Let's assume we have a DB with Folders and Documents tables. Each folder contains multiple documents.
In our DB we have 1000 folders and total 100,000 documents.
We need to provide user a quick search for these documents, and ElasticSearch is doing it's job perfectly at the moment. We have a Documents index where we contain each document data and it's folder name.
But now we have a new requirement - we must add some kind of permissions system for our search. We should be able to authorize user to search only for documents, containing in particular folders. Each user must have a list of folders, which he can access. We can't create roles, because we should be able to tune up permissions for each user individually.
For example user John is authorized to search only for documents from folders "A", "B" and "C". It's not a problem, because we can use filter for our query.
But what if user is authorized to search for 500 folders? I don't think it's a good idea to filter the documents by 500 folder names.
What can you recommend to do in this situation?
