summaryrefslogtreecommitdiffstats
path: root/apps
diff options
context:
space:
mode:
authorJoas Schilling <coding@schilljs.com>2023-03-16 08:41:18 +0100
committerJoas Schilling <coding@schilljs.com>2023-03-16 08:44:41 +0100
commit9ba091b348e54acc661f313546d59b4aca68a871 (patch)
tree9a975c25fe9c8648fda60815d788b77b0022a21d /apps
parent15b80b6c1ab1d9fc122c4c04dd48c49c1a5d5219 (diff)
downloadnextcloud-server-9ba091b348e54acc661f313546d59b4aca68a871.tar.gz
nextcloud-server-9ba091b348e54acc661f313546d59b4aca68a871.zip
fix(workflow): Check tag attribute
Signed-off-by: Joas Schilling <coding@schilljs.com>
Diffstat (limited to 'apps')
-rw-r--r--apps/workflowengine/lib/Check/FileSystemTags.php37
1 files changed, 29 insertions, 8 deletions
diff --git a/apps/workflowengine/lib/Check/FileSystemTags.php b/apps/workflowengine/lib/Check/FileSystemTags.php
index 008f47eca78..351364c5562 100644
--- a/apps/workflowengine/lib/Check/FileSystemTags.php
+++ b/apps/workflowengine/lib/Check/FileSystemTags.php
@@ -30,7 +30,10 @@ use OCA\Files_Sharing\SharedStorage;
use OCA\WorkflowEngine\Entity\File;
use OCP\Files\Cache\ICache;
use OCP\Files\IHomeStorage;
+use OCP\IGroupManager;
use OCP\IL10N;
+use OCP\IUser;
+use OCP\IUserSession;
use OCP\SystemTag\ISystemTagManager;
use OCP\SystemTag\ISystemTagObjectMapper;
use OCP\SystemTag\TagNotFoundException;
@@ -55,16 +58,23 @@ class FileSystemTags implements ICheck, IFileCheck {
/** @var ISystemTagObjectMapper */
protected $systemTagObjectMapper;
-
- /**
- * @param IL10N $l
- * @param ISystemTagManager $systemTagManager
- * @param ISystemTagObjectMapper $systemTagObjectMapper
- */
- public function __construct(IL10N $l, ISystemTagManager $systemTagManager, ISystemTagObjectMapper $systemTagObjectMapper) {
+ /** @var IUserSession */
+ protected $userSession;
+ /** @var IGroupManager */
+ protected $groupManager;
+
+ public function __construct(
+ IL10N $l,
+ ISystemTagManager $systemTagManager,
+ ISystemTagObjectMapper $systemTagObjectMapper,
+ IUserSession $userSession,
+ IGroupManager $groupManager
+ ) {
$this->l = $l;
$this->systemTagManager = $systemTagManager;
$this->systemTagObjectMapper = $systemTagObjectMapper;
+ $this->userSession = $userSession;
+ $this->groupManager = $groupManager;
}
/**
@@ -88,7 +98,18 @@ class FileSystemTags implements ICheck, IFileCheck {
}
try {
- $this->systemTagManager->getTagsByIds($value);
+ $tags = $this->systemTagManager->getTagsByIds($value);
+
+ $user = $this->userSession->getUser();
+ $isAdmin = $user instanceof IUser && $this->groupManager->isAdmin($user->getUID());
+
+ if (!$isAdmin) {
+ foreach ($tags as $tag) {
+ if (!$tag->isUserVisible()) {
+ throw new \UnexpectedValueException($this->l->t('The given tag id is invalid'), 4);
+ }
+ }
+ }
} catch (TagNotFoundException $e) {
throw new \UnexpectedValueException($this->l->t('The given tag id is invalid'), 2);
} catch (\InvalidArgumentException $e) {