aboutsummaryrefslogtreecommitdiffstats
path: root/apps/dav/appinfo/v1/publicwebdav.php
diff options
context:
space:
mode:
authorRobin Appelman <icewind@owncloud.com>2015-12-03 15:29:42 +0100
committerRobin Appelman <icewind@owncloud.com>2016-02-09 15:02:34 +0100
commitfd9166488b5924aba74d3f77bb6795be03501c81 (patch)
tree580c98e4aac9fafd0cfb8b8de6804a3d0ca37c35 /apps/dav/appinfo/v1/publicwebdav.php
parenta6ade67dfbbae562634e9cce47d53f1aa78ad7e4 (diff)
downloadnextcloud-server-fd9166488b5924aba74d3f77bb6795be03501c81.tar.gz
nextcloud-server-fd9166488b5924aba74d3f77bb6795be03501c81.zip
Check that the owner of a link share still has share permissions on access
Diffstat (limited to 'apps/dav/appinfo/v1/publicwebdav.php')
-rw-r--r--apps/dav/appinfo/v1/publicwebdav.php8
1 files changed, 7 insertions, 1 deletions
diff --git a/apps/dav/appinfo/v1/publicwebdav.php b/apps/dav/appinfo/v1/publicwebdav.php
index 6ddb570aca8..b0ee264aac3 100644
--- a/apps/dav/appinfo/v1/publicwebdav.php
+++ b/apps/dav/appinfo/v1/publicwebdav.php
@@ -46,7 +46,9 @@ $serverFactory = new OCA\DAV\Connector\Sabre\ServerFactory(
$requestUri = \OC::$server->getRequest()->getRequestUri();
-$server = $serverFactory->createServer($baseuri, $requestUri, $authBackend, function () use ($authBackend) {
+$linkCheckPlugin = new \OCA\DAV\Files\Sharing\PublicLinkCheckPlugin();
+
+$server = $serverFactory->createServer($baseuri, $requestUri, $authBackend, function (\Sabre\DAV\Server $server) use ($authBackend, $linkCheckPlugin) {
$isAjax = (isset($_SERVER['HTTP_X_REQUESTED_WITH']) && $_SERVER['HTTP_X_REQUESTED_WITH'] === 'XMLHttpRequest');
if (OCA\Files_Sharing\Helper::isOutgoingServer2serverShareEnabled() === false && !$isAjax) {
// this is what is thrown when trying to access a non-existing share
@@ -68,9 +70,13 @@ $server = $serverFactory->createServer($baseuri, $requestUri, $authBackend, func
OC_Util::setupFS($owner);
$ownerView = \OC\Files\Filesystem::getView();
$path = $ownerView->getPath($fileId);
+ $fileInfo = $ownerView->getFileInfo($path);
+ $linkCheckPlugin->setFileInfo($fileInfo);
return new \OC\Files\View($ownerView->getAbsolutePath($path));
});
+$server->addPlugin($linkCheckPlugin);
+
// And off we go!
$server->exec();