diff options
author | John Molakvoæ <skjnldsv@protonmail.com> | 2023-09-01 13:53:41 +0200 |
---|---|---|
committer | backportbot-nextcloud[bot] <backportbot-nextcloud[bot]@users.noreply.github.com> | 2023-09-04 09:05:11 +0000 |
commit | d60f95833bb3afc4838f71950d4a023710c236f7 (patch) | |
tree | d4faf5892e300c9b1694b4f8e256bc1f5af18ba2 /lib | |
parent | 09fd427df1e3cb6b1c41b7b1efabcd15b9da4118 (diff) | |
download | nextcloud-server-d60f95833bb3afc4838f71950d4a023710c236f7.tar.gz nextcloud-server-d60f95833bb3afc4838f71950d4a023710c236f7.zip |
fix: prevent sharing permissions on user root folder
Signed-off-by: John Molakvoæ <skjnldsv@protonmail.com>
Diffstat (limited to 'lib')
-rw-r--r-- | lib/private/Files/Node/LazyUserFolder.php | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/lib/private/Files/Node/LazyUserFolder.php b/lib/private/Files/Node/LazyUserFolder.php index 8fbdec4b49d..7093f5ebd8f 100644 --- a/lib/private/Files/Node/LazyUserFolder.php +++ b/lib/private/Files/Node/LazyUserFolder.php @@ -63,7 +63,8 @@ class LazyUserFolder extends LazyFolder { } }, [ 'path' => $this->path, - 'permissions' => Constants::PERMISSION_ALL, + // Sharing user root folder is not allowed + 'permissions' => Constants::PERMISSION_ALL ^ Constants::PERMISSION_SHARE, 'type' => FileInfo::TYPE_FOLDER, 'mimetype' => FileInfo::MIMETYPE_FOLDER, ]); |