summaryrefslogtreecommitdiffstats
path: root/lib
diff options
context:
space:
mode:
authorJohn Molakvoæ <skjnldsv@protonmail.com>2023-09-01 13:53:41 +0200
committerbackportbot-nextcloud[bot] <backportbot-nextcloud[bot]@users.noreply.github.com>2023-09-04 09:05:11 +0000
commitd60f95833bb3afc4838f71950d4a023710c236f7 (patch)
treed4faf5892e300c9b1694b4f8e256bc1f5af18ba2 /lib
parent09fd427df1e3cb6b1c41b7b1efabcd15b9da4118 (diff)
downloadnextcloud-server-d60f95833bb3afc4838f71950d4a023710c236f7.tar.gz
nextcloud-server-d60f95833bb3afc4838f71950d4a023710c236f7.zip
fix: prevent sharing permissions on user root folder
Signed-off-by: John Molakvoæ <skjnldsv@protonmail.com>
Diffstat (limited to 'lib')
-rw-r--r--lib/private/Files/Node/LazyUserFolder.php3
1 files changed, 2 insertions, 1 deletions
diff --git a/lib/private/Files/Node/LazyUserFolder.php b/lib/private/Files/Node/LazyUserFolder.php
index 8fbdec4b49d..7093f5ebd8f 100644
--- a/lib/private/Files/Node/LazyUserFolder.php
+++ b/lib/private/Files/Node/LazyUserFolder.php
@@ -63,7 +63,8 @@ class LazyUserFolder extends LazyFolder {
}
}, [
'path' => $this->path,
- 'permissions' => Constants::PERMISSION_ALL,
+ // Sharing user root folder is not allowed
+ 'permissions' => Constants::PERMISSION_ALL ^ Constants::PERMISSION_SHARE,
'type' => FileInfo::TYPE_FOLDER,
'mimetype' => FileInfo::MIMETYPE_FOLDER,
]);