From 750a9f2c4a966471aa3e305502f8c81c7ca73a6d Mon Sep 17 00:00:00 2001 From: John Molakvoæ Date: Fri, 1 Sep 2023 13:53:41 +0200 Subject: fix: prevent sharing permissions on user root folder MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: John Molakvoæ --- lib/private/Files/Node/LazyUserFolder.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'lib') diff --git a/lib/private/Files/Node/LazyUserFolder.php b/lib/private/Files/Node/LazyUserFolder.php index 8fbdec4b49d..7093f5ebd8f 100644 --- a/lib/private/Files/Node/LazyUserFolder.php +++ b/lib/private/Files/Node/LazyUserFolder.php @@ -63,7 +63,8 @@ class LazyUserFolder extends LazyFolder { } }, [ 'path' => $this->path, - 'permissions' => Constants::PERMISSION_ALL, + // Sharing user root folder is not allowed + 'permissions' => Constants::PERMISSION_ALL ^ Constants::PERMISSION_SHARE, 'type' => FileInfo::TYPE_FOLDER, 'mimetype' => FileInfo::MIMETYPE_FOLDER, ]); -- cgit v1.2.3