]> source.dussan.org Git - nextcloud-server.git/commitdiff
Repair step for link shares
authorRoeland Jago Douma <roeland@famdouma.nl>
Mon, 15 Apr 2019 19:19:32 +0000 (21:19 +0200)
committerRoeland Jago Douma <roeland@famdouma.nl>
Wed, 17 Apr 2019 08:17:28 +0000 (10:17 +0200)
Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl>
core/Application.php
core/Notification/RemoveLinkSharesNotifier.php [new file with mode: 0644]
lib/composer/composer/autoload_classmap.php
lib/composer/composer/autoload_static.php
lib/private/Repair.php
lib/private/Repair/RemoveLinkShares.php [new file with mode: 0644]
version.php

index 5ba07e2cb481cabb2d79933f6b9612dd5cfd92e1..f89b7e480814c2d084922c109f30ce225f9727f3 100644 (file)
@@ -28,6 +28,7 @@
 
 namespace OC\Core;
 
+use OC\Core\Notification\RemoveLinkSharesNotifier;
 use OC\DB\MissingIndexInformation;
 use OC\DB\SchemaWrapper;
 use OCP\AppFramework\App;
@@ -54,6 +55,18 @@ class Application extends App {
                $server = $container->getServer();
                $eventDispatcher = $server->getEventDispatcher();
 
+               $notificationManager = $server->getNotificationManager();
+               $notificationManager->registerNotifier(function() use ($server) {
+                       return new RemoveLinkSharesNotifier(
+                               $server->getL10NFactory()
+                       );
+               },  function() use ($server) {
+                       return [
+                               'id' => 'core',
+                               'name' => 'core',
+                       ];
+               });
+
                $eventDispatcher->addListener(IDBConnection::CHECK_MISSING_INDEXES_EVENT,
                        function(GenericEvent $event) use ($container) {
                                /** @var MissingIndexInformation $subject */
diff --git a/core/Notification/RemoveLinkSharesNotifier.php b/core/Notification/RemoveLinkSharesNotifier.php
new file mode 100644 (file)
index 0000000..b77846c
--- /dev/null
@@ -0,0 +1,55 @@
+<?php
+declare(strict_types=1);
+/**
+ * @copyright Copyright (c) 2019, Roeland Jago Douma <roeland@famdouma.nl>
+ *
+ * @author Roeland Jago Douma <roeland@famdouma.nl>
+ *
+ * @license GNU AGPL version 3 or any later version
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as
+ * published by the Free Software Foundation, either version 3 of the
+ * License, or (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program.  If not, see <http://www.gnu.org/licenses/>.
+ *
+ */
+
+namespace OC\Core\Notification;
+
+use OCP\L10N\IFactory;
+use OCP\Notification\INotification;
+use OCP\Notification\INotifier;
+
+class RemoveLinkSharesNotifier implements INotifier {
+       /** @var IFactory */
+       private $l10nFactory;
+
+       public function __construct(IFactory $factory) {
+               $this->l10nFactory = $factory;
+       }
+
+       public function prepare(INotification $notification, $languageCode): INotification {
+               if($notification->getApp() !== 'core') {
+                       throw new \InvalidArgumentException();
+               }
+               $l = $this->l10nFactory->get('core', $languageCode);
+
+               if ($notification->getSubject() === 'repair_exposing_links') {
+                       $notification->setParsedSubject($l->t('Some of your link shares have been removed'));
+                       $notification->setParsedMessage($l->t('Due to a security bug we had to remove some of your link shares. Please see the link for more information.'));
+                       $notification->setLink('https://nextcloud.com/security/advisory/?id=NC-SA-2019-003');
+                       return $notification;
+               }
+
+               throw new \InvalidArgumentException('Invalid subject');
+       }
+
+}
index a0fe19e01182213806b4ad11cad758f1e3b14a74..cad7c21a5943738882375864203a760cc5bc5211 100644 (file)
@@ -711,6 +711,7 @@ return array(
     'OC\\Core\\Migrations\\Version15000Date20181029084625' => $baseDir . '/core/Migrations/Version15000Date20181029084625.php',
     'OC\\Core\\Migrations\\Version16000Date20190207141427' => $baseDir . '/core/Migrations/Version16000Date20190207141427.php',
     'OC\\Core\\Migrations\\Version16000Date20190212081545' => $baseDir . '/core/Migrations/Version16000Date20190212081545.php',
+    'OC\\Core\\Notification\\RemoveLinkSharesNotifier' => $baseDir . '/core/Notification/RemoveLinkSharesNotifier.php',
     'OC\\Core\\Service\\LoginFlowV2Service' => $baseDir . '/core/Service/LoginFlowV2Service.php',
     'OC\\DB\\Adapter' => $baseDir . '/lib/private/DB/Adapter.php',
     'OC\\DB\\AdapterMySQL' => $baseDir . '/lib/private/DB/AdapterMySQL.php',
@@ -1018,6 +1019,7 @@ return array(
     'OC\\Repair\\OldGroupMembershipShares' => $baseDir . '/lib/private/Repair/OldGroupMembershipShares.php',
     'OC\\Repair\\Owncloud\\DropAccountTermsTable' => $baseDir . '/lib/private/Repair/Owncloud/DropAccountTermsTable.php',
     'OC\\Repair\\Owncloud\\SaveAccountsTableData' => $baseDir . '/lib/private/Repair/Owncloud/SaveAccountsTableData.php',
+    'OC\\Repair\\RemoveLinkShares' => $baseDir . '/lib/private/Repair/RemoveLinkShares.php',
     'OC\\Repair\\RemoveRootShares' => $baseDir . '/lib/private/Repair/RemoveRootShares.php',
     'OC\\Repair\\RepairInvalidShares' => $baseDir . '/lib/private/Repair/RepairInvalidShares.php',
     'OC\\Repair\\RepairMimeTypes' => $baseDir . '/lib/private/Repair/RepairMimeTypes.php',
index 3dcca438cb67d19a85ad9a523e9ac84f42ca1019..7a49d254e904cc253ae130abcea9cb9342031686 100644 (file)
@@ -741,6 +741,7 @@ class ComposerStaticInit53792487c5a8370acc0b06b1a864ff4c
         'OC\\Core\\Migrations\\Version15000Date20181029084625' => __DIR__ . '/../../..' . '/core/Migrations/Version15000Date20181029084625.php',
         'OC\\Core\\Migrations\\Version16000Date20190207141427' => __DIR__ . '/../../..' . '/core/Migrations/Version16000Date20190207141427.php',
         'OC\\Core\\Migrations\\Version16000Date20190212081545' => __DIR__ . '/../../..' . '/core/Migrations/Version16000Date20190212081545.php',
+        'OC\\Core\\Notification\\RemoveLinkSharesNotifier' => __DIR__ . '/../../..' . '/core/Notification/RemoveLinkSharesNotifier.php',
         'OC\\Core\\Service\\LoginFlowV2Service' => __DIR__ . '/../../..' . '/core/Service/LoginFlowV2Service.php',
         'OC\\DB\\Adapter' => __DIR__ . '/../../..' . '/lib/private/DB/Adapter.php',
         'OC\\DB\\AdapterMySQL' => __DIR__ . '/../../..' . '/lib/private/DB/AdapterMySQL.php',
@@ -1048,6 +1049,7 @@ class ComposerStaticInit53792487c5a8370acc0b06b1a864ff4c
         'OC\\Repair\\OldGroupMembershipShares' => __DIR__ . '/../../..' . '/lib/private/Repair/OldGroupMembershipShares.php',
         'OC\\Repair\\Owncloud\\DropAccountTermsTable' => __DIR__ . '/../../..' . '/lib/private/Repair/Owncloud/DropAccountTermsTable.php',
         'OC\\Repair\\Owncloud\\SaveAccountsTableData' => __DIR__ . '/../../..' . '/lib/private/Repair/Owncloud/SaveAccountsTableData.php',
+        'OC\\Repair\\RemoveLinkShares' => __DIR__ . '/../../..' . '/lib/private/Repair/RemoveLinkShares.php',
         'OC\\Repair\\RemoveRootShares' => __DIR__ . '/../../..' . '/lib/private/Repair/RemoveRootShares.php',
         'OC\\Repair\\RepairInvalidShares' => __DIR__ . '/../../..' . '/lib/private/Repair/RepairInvalidShares.php',
         'OC\\Repair\\RepairMimeTypes' => __DIR__ . '/../../..' . '/lib/private/Repair/RepairMimeTypes.php',
index e4eb4cfcc1638250bffbaf686c0d9b2b8dca9657..d27e6b812b33e511d52cd04a8e8090f750289034 100644 (file)
@@ -48,6 +48,7 @@ use OC\Repair\NC16\CleanupCardDAVPhotoCache;
 use OC\Repair\OldGroupMembershipShares;
 use OC\Repair\Owncloud\DropAccountTermsTable;
 use OC\Repair\Owncloud\SaveAccountsTableData;
+use OC\Repair\RemoveLinkShares;
 use OC\Repair\RemoveRootShares;
 use OC\Repair\RepairInvalidShares;
 use OC\Repair\RepairMimeTypes;
@@ -55,6 +56,7 @@ use OC\Repair\SqliteAutoincrement;
 use OC\Template\JSCombiner;
 use OC\Template\SCSSCacher;
 use OCP\AppFramework\QueryException;
+use OCP\AppFramework\Utility\ITimeFactory;
 use OCP\Migration\IOutput;
 use OCP\Migration\IRepairStep;
 use Symfony\Component\EventDispatcher\EventDispatcherInterface;
@@ -152,6 +154,7 @@ class Repair implements IOutput {
                        new SetVcardDatabaseUID(\OC::$server->getDatabaseConnection(), \OC::$server->getConfig(), \OC::$server->getLogger()),
                        new CleanupCardDAVPhotoCache(\OC::$server->getConfig(), \OC::$server->getAppDataDir('dav-photocache'), \OC::$server->getLogger()),
                        new AddClenupLoginFlowV2BackgroundJob(\OC::$server->getJobList()),
+                       new RemoveLinkShares(\OC::$server->getDatabaseConnection(), \OC::$server->getConfig(), \OC::$server->getGroupManager(), \OC::$server->getNotificationManager(), \OC::$server->query(ITimeFactory::class)),
                ];
        }
 
diff --git a/lib/private/Repair/RemoveLinkShares.php b/lib/private/Repair/RemoveLinkShares.php
new file mode 100644 (file)
index 0000000..084a65a
--- /dev/null
@@ -0,0 +1,221 @@
+<?php
+declare(strict_types=1);
+/**
+ * @copyright Copyright (c) 2019, Roeland Jago Douma <roeland@famdouma.nl>
+ *
+ * @author Roeland Jago Douma <roeland@famdouma.nl>
+ *
+ * @license GNU AGPL version 3 or any later version
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as
+ * published by the Free Software Foundation, either version 3 of the
+ * License, or (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program.  If not, see <http://www.gnu.org/licenses/>.
+ *
+ */
+
+namespace OC\Repair;
+
+use Doctrine\DBAL\Driver\Statement;
+use OCP\AppFramework\Utility\ITimeFactory;
+use OCP\IConfig;
+use OCP\IDBConnection;
+use OCP\IGroupManager;
+use OCP\Migration\IOutput;
+use OCP\Migration\IRepairStep;
+use OCP\Notification\IManager;
+
+class RemoveLinkShares implements IRepairStep {
+       /** @var IDBConnection */
+       private $connection;
+       /** @var IConfig */
+       private $config;
+       /** @var string[] */
+       private $userToNotify = [];
+       /** @var IGroupManager */
+       private $groupManager;
+       /** @var IManager */
+       private $notificationManager;
+       /** @var ITimeFactory */
+       private $timeFactory;
+
+       public function __construct(IDBConnection $connection,
+                                                               IConfig $config,
+                                                               IGroupManager $groupManager,
+                                                               IManager $notificationManager,
+                                                               ITimeFactory $timeFactory) {
+               $this->connection = $connection;
+               $this->config = $config;
+               $this->groupManager = $groupManager;
+               $this->notificationManager = $notificationManager;
+               $this->timeFactory = $timeFactory;
+       }
+
+
+       public function getName(): string {
+               return 'Remove potentially over exposing share links';
+       }
+
+       private function shouldRun(): bool {
+               $versionFromBeforeUpdate = $this->config->getSystemValue('version', '0.0.0');
+
+               if (version_compare($versionFromBeforeUpdate, '14.0.11', '<')) {
+                       return true;
+               }
+               if (version_compare($versionFromBeforeUpdate, '15.0.8', '<')) {
+                       return true;
+               }
+               if (version_compare($versionFromBeforeUpdate, '16.0.0', '<=')) {
+                       return true;
+               }
+
+               return false;
+       }
+
+       /**
+        * Delete the share
+        *
+        * @param int $id
+        */
+       private function deleteShare(int $id) {
+               $qb = $this->connection->getQueryBuilder();
+               $qb->delete('share')
+                       ->where($qb->expr()->eq('id', $qb->createNamedParameter($id)));
+               $qb->execute();
+       }
+
+       /**
+        * Get the total of affected shares
+        *
+        * @return int
+        */
+       private function getTotal(): int {
+               $sql = 'SELECT COUNT(*) AS `total`
+               FROM `*PREFIX*share`
+               WHERE `id` IN (
+                       SELECT `s1`.`id`
+                       FROM (
+                               SELECT *
+                               FROM `*PREFIX*share`
+                               WHERE `parent` IS NOT NULL
+                               AND `share_type` = 3
+                       ) AS s1
+                       JOIN `*PREFIX*share` AS s2
+                       ON `s1`.`parent` = `s2`.`id`
+                       WHERE (`s2`.`share_type` = 1 OR `s2`.`share_type` = 2)
+                       AND `s1`.`item_source` = `s2`.`item_source`
+               )';
+               $cursor = $this->connection->executeQuery($sql);
+               $data = $cursor->fetchAll();
+               $total = (int)$data[0]['total'];
+               $cursor->closeCursor();
+
+               return $total;
+       }
+
+       /**
+        * Get the cursor to fetch all the shares
+        *
+        * @return \Doctrine\DBAL\Driver\Statement
+        */
+       private function getShares(): Statement {
+               $sql = 'SELECT `s1`.`id`, `s1`.`uid_owner`, `s1`.`uid_initiator`
+                       FROM (
+                               SELECT *
+                               FROM `*PREFIX*share`
+                               WHERE `parent` IS NOT NULL
+                               AND `share_type` = 3
+                       ) AS s1
+                       JOIN `*PREFIX*share` AS s2
+                       ON `s1`.`parent` = `s2`.`id`
+                       WHERE (`s2`.`share_type` = 1 OR `s2`.`share_type` = 2)
+                       AND `s1`.`item_source` = `s2`.`item_source`';
+               $cursor = $this->connection->executeQuery($sql);
+               return $cursor;
+       }
+
+       /**
+        * Process a single share
+        *
+        * @param array $data
+        */
+       private function processShare(array $data) {
+               $id = $data['id'];
+
+               $this->addToNotify($data['uid_owner']);
+               $this->addToNotify($data['uid_initiator']);
+
+               $this->deleteShare((int)$id);
+       }
+
+       /**
+        * Update list of users to notify
+        *
+        * @param string $uid
+        */
+       private function addToNotify(string $uid) {
+               if (!isset($this->userToNotify[$uid])) {
+                       $this->userToNotify[$uid] = true;
+               }
+       }
+
+       /**
+        * Send all notifications
+        */
+       private function sendNotification() {
+               $time = $this->timeFactory->getDateTime();
+
+               $notification = $this->notificationManager->createNotification();
+               $notification->setApp('core')
+                       ->setDateTime($time)
+                       ->setObject('repair', 'exposing_links')
+                       ->setSubject('repair_exposing_links', []);
+
+               $users = array_keys($this->userToNotify);
+               foreach ($users as $user) {
+                       $notification->setUser($user);
+                       $this->notificationManager->notify($notification);
+               }
+       }
+
+       private function repair(IOutput $output) {
+               $total = $this->getTotal();
+               $output->startProgress($total);
+
+               $shareCursor = $this->getShares();
+               while($data = $shareCursor->fetch()) {
+                       $this->processShare($data);
+                       $output->advance();
+               }
+               $output->finishProgress();
+               $shareCursor->closeCursor();
+
+               // Notifiy all admins
+               $adminGroup = $this->groupManager->get('admin');
+               $adminUsers = $adminGroup->getUsers();
+               foreach ($adminUsers as $user) {
+                       $this->addToNotify($user->getUID());
+               }
+
+               $output->info('Sending notifications to admins and affected users');
+               $this->sendNotification();
+       }
+
+       public function run(IOutput $output) {
+               if ($this->shouldRun()) {
+                       $output->info('Removing potentially over exposing link shares');
+                       $this->repair($output);
+                       $output->info('Removed potentially over exposing link shares');
+               } else {
+                       $output->info('No need to remove link shares.');
+               }
+       }
+}
index 6d79827ed11ae2101162577ecf1e888ad185e6fa..596cfc2bf1957c5a469388d61a9b99e6767844e7 100644 (file)
@@ -29,7 +29,7 @@
 // between betas, final and RCs. This is _not_ the public version number. Reset minor/patchlevel
 // when updating major/minor version number.
 
-$OC_Version = array(16, 0, 0, 6);
+$OC_Version = array(16, 0, 0, 7);
 
 // The human readable string
 $OC_VersionString = '16.0.0 RC 1';