I currently have an in-house Confluence EventListener add-on that sends content from Confluence ContentEvents to our DevOps Kafka bus. However, we have found that content marked in the UI as Private (or otherwise "not shared") is happily sent to the Listener and we happily send the private content to the Kafka bus for everyone to see. 
All the references I've seen seem to focus on "does a specific user have permission". However, we need the filter to answer the question "is this shared with EVERYONE", and I have not found an ALL_USERS constant.
Currently, I'm experimenting down a trial-and-error path of something like:
boolean isShared(ContentEntityObject content){
return ((content.sharedAccessAllowed((String)null)) &&
(content.sharedAccessAllowed((User)null)) &&
(!content.hasContentPermissions()));
}But some documentation suggests restrictive permissions from the Ancestry of the content (parent Pages or Space) are not provided in the List of ContentPermissions provided for the specific instance of content?
Is there more information available for identifying only fully shared content that has no restrictions whatsoever? Or, more precisely, that a specific piece of content (Page, Blog, Comment) has no restriction on it--including inherited restrictions/permission?