diff options
author | Thomas Müller <thomas.mueller@tmit.eu> | 2016-03-01 09:22:08 +0100 |
---|---|---|
committer | Thomas Müller <thomas.mueller@tmit.eu> | 2016-03-01 09:22:08 +0100 |
commit | 25a4571dcd54b9db082ca9b2aa70924b4dc6f18d (patch) | |
tree | c6a83231afffac1f8a9c4561a1b26b9c3708490e /apps/dav/lib/connector | |
parent | fd4742d4308aef6e1d628e19cece5cc04aaee481 (diff) | |
parent | d04edfaf0dee3c2f1b4347a4ed36a79477d4a3f9 (diff) | |
download | nextcloud-server-25a4571dcd54b9db082ca9b2aa70924b4dc6f18d.tar.gz nextcloud-server-25a4571dcd54b9db082ca9b2aa70924b4dc6f18d.zip |
Merge pull request #22731 from owncloud/hide-nodes-from-listening
Hides nodes from listing that the user has no access to
Diffstat (limited to 'apps/dav/lib/connector')
-rw-r--r-- | apps/dav/lib/connector/legacydavacl.php | 4 | ||||
-rw-r--r-- | apps/dav/lib/connector/sabre/davaclplugin.php | 72 |
2 files changed, 74 insertions, 2 deletions
diff --git a/apps/dav/lib/connector/legacydavacl.php b/apps/dav/lib/connector/legacydavacl.php index 149bd85e4be..5a654606465 100644 --- a/apps/dav/lib/connector/legacydavacl.php +++ b/apps/dav/lib/connector/legacydavacl.php @@ -21,10 +21,10 @@ namespace OCA\DAV\Connector; - +use OCA\DAV\Connector\Sabre\DavAclPlugin; use Sabre\HTTP\URLUtil; -class LegacyDAVACL extends \Sabre\DAVACL\Plugin { +class LegacyDAVACL extends DavAclPlugin { /** * Converts the v1 principal `principal/<username>` to the new v2 diff --git a/apps/dav/lib/connector/sabre/davaclplugin.php b/apps/dav/lib/connector/sabre/davaclplugin.php new file mode 100644 index 00000000000..4a9dd66161d --- /dev/null +++ b/apps/dav/lib/connector/sabre/davaclplugin.php @@ -0,0 +1,72 @@ +<?php +/** + * @author Lukas Reschke <lukas@owncloud.com> + * + * @copyright Copyright (c) 2016, ownCloud, Inc. + * @license AGPL-3.0 + * + * This code is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License, version 3, + * as published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License, version 3, + * along with this program. If not, see <http://www.gnu.org/licenses/> + * + */ + +namespace OCA\DAV\Connector\Sabre; + +use Sabre\DAV\Exception\NotFound; +use Sabre\DAV\IFile; +use Sabre\DAV\INode; +use \Sabre\DAV\PropFind; +use \Sabre\DAV\PropPatch; +use Sabre\DAVACL\Exception\NeedPrivileges; +use \Sabre\HTTP\RequestInterface; +use \Sabre\HTTP\ResponseInterface; +use Sabre\HTTP\URLUtil; + +/** + * Class DavAclPlugin is a wrapper around \Sabre\DAVACL\Plugin that returns 404 + * responses in case the resource to a response has been forbidden instead of + * a 403. This is used to prevent enumeration of valid resources. + * + * @see https://github.com/owncloud/core/issues/22578 + * @package OCA\DAV\Connector\Sabre + */ +class DavAclPlugin extends \Sabre\DAVACL\Plugin { + public function __construct() { + $this->hideNodesFromListings = true; + } + + function checkPrivileges($uri, $privileges, $recursion = self::R_PARENT, $throwExceptions = true) { + $access = parent::checkPrivileges($uri, $privileges, $recursion, false); + if($access === false) { + /** @var INode $node */ + $node = $this->server->tree->getNodeForPath($uri); + + switch(get_class($node)) { + case 'OCA\DAV\CardDAV\AddressBook': + $type = 'Addressbook'; + break; + default: + $type = 'Node'; + break; + } + throw new NotFound( + sprintf( + "%s with name '%s' could not be found", + $type, + $node->getName() + ) + ); + } + + return $access; + } +} |