Age | Commit message (Collapse) | Author |
|
|
|
|
|
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
This involved changing CacheQueryBuilder\whereParentIn to take a
parameter name, renaming the function accordingly.
Signed-off-by: Sijmen Schoon <me@sijmenschoon.nl>
|
|
Signed-off-by: Sijmen Schoon <me@sijmenschoon.nl>
|
|
[stable21] Handle files with `is_file` instead of `file_exists`
|
|
Make sure that when a user copy a file from a directory they don't have
all permissions to a directory where they have more permissions, the
permissions are correctly set to the one from the parent taget folder.
This was caused by the ObjectStoreStorage::copyFromStorage using
the jailed storage and cache entry instead of the unjailed one like other
storages (the local one).
Steps to reproduce
+ Use object storage
+ Create a groupfolder with one group having full permission and another one
who can just read files.
+ With an user who is in the second group, copy a file from the groupfolder to
the home folder of this user.
+ The file in the home folder of the user will be read only and can't be deleted
even though it is in their home folder and they are the owner. In oc_filecache,
the permissions stored for this file are 1 (READ)
Signed-off-by: Carl Schwan <carl@carlschwan.eu>
|
|
Signed-off-by: Robin Appelman <robin@icewind.nl>
|
|
Signed-off-by: Robin Appelman <robin@icewind.nl>
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
[stable21] Make the route name error more helpful
|
|
Should fix things like `fread(): read of 8192 bytes failed with errno=21 Is a directory`
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
As a developer I have no clue what "Invalid route name" means. If the
exception gives me a hint I might find it easier to figure out why my
route triggers this error.
Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
|
|
[stable21] Fix security issues when copying groupfolder with advanced ACL
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
Using advanced ACL, it is possible that an user has access to a
directory but not to a subdirectory, so the copying use
Common::copyFromStorage instead of Local::copyFromStorage.
Fix https://github.com/nextcloud/groupfolders/issues/1692
Signed-off-by: Carl Schwan <carl@carlschwan.eu>
|
|
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
Signed-off-by: Nextcloud bot <bot@nextcloud.com>
|
|
|
|
Signed-off-by: Joas Schilling <coding@schilljs.com>
|
|
mysql really likes to pick an index for sorting if it can't fully satisfy the where
filter with an index, since search queries pretty much never are fully filtered by index
mysql often picks an index for sorting instead of the *much* more useful index for filtering.
To bypass this, we tell mysql explicitly not to use the mtime (the default order field) index,
so it will instead pick an index that is actually useful.
Signed-off-by: Robin Appelman <robin@icewind.nl>
|
|
Signed-off-by: Robin Appelman <robin@icewind.nl>
|
|
|
|
|
|
Should make sense.
|
|
[stable21] Properly handle folder deletion on external s3 storage
|
|
[stable21] Add proper message to created share not found
|
|
[stable21] Keep group restrictions when reenabling apps after an update
|
|
Signed-off-by: Joas Schilling <coding@schilljs.com>
|
|
Signed-off-by: Joas Schilling <coding@schilljs.com>
|
|
Signed-off-by: John Molakvoæ (skjnldsv) <skjnldsv@protonmail.com>
|
|
Signed-off-by: John Molakvoæ (skjnldsv) <skjnldsv@protonmail.com>
|
|
[stable21] Keep pw based auth tokens valid when pw-less login happens
|
|
[21] generate a better optimized query for path prefix search filters
|
|
Signed-off-by: Robin Appelman <robin@icewind.nl>
|
|
Signed-off-by: Bjoern Schiessle <bjoern@schiessle.org>
|
|
[stable21] Fix Lots of Error: file_exists(): open_basedir restriction in effect
|
|
|
|
[stable21] Don't further setup disabled users when logging in with apache
|
|
Signed-off-by: Joas Schilling <coding@schilljs.com>
|
|
Signed-off-by: Julius Härtl <jus@bitgrid.net>
|
|
another storage
Signed-off-by: Julius Härtl <jus@bitgrid.net>
|
|
Signed-off-by: Daniel Kesselberg <mail@danielkesselberg.de>
|
|
Signed-off-by: Daniel Kesselberg <mail@danielkesselberg.de>
|
|
Signed-off-by: Vincent Petry <vincent@nextcloud.com>
|