You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
When a guest "Saves as", guest can save in the folder of the user who created the share.
To Reproduce
Steps to reproduce the behavior:
USER creates a folder and shares a link with write access.
GUEST enters the folder, creates an Opendocument sheet, and opens it via Nextcloud Richdocuments app, with CODE.
GUEST "Saves as" or ("Export") to /File.ods
Expected behavior
The "/" is related to the files of USER, not to the share.
GUEST should be restricted to writing in the shared folder only.
Screenshots
N/A
Client details:
OS: Linux
Browser Chromium
Version 126.0.6478.126
Device: desktop
Server details
Operating system:
Fedora
Web server:
Apache
Database:
Mariadb
PHP version:
8.3.8
Nextcloud version:
29.0.3
Version of the richdocuments app
8.4.3
Version of Collabora Online
COOLWSD version:
24.04.4.2 git hash: fbf97e9 (E)
Hello,
Thanks for reading and trying to reproduce.
I did retry, with same behavior.
Perhaps I was not clear enough: I share the folder as a link to a person
who does not have an account. So per se, there is no GUEST root folder,
just access through web interface to the USER's /shared folder.
Is it what you did, or did GUEST have an account ?
Since one could not override existing files, I did not report it as
security, but I guess one GUEST can mess up the folders of the sharing user
and that can be some deal.
Do you recommend I report it as a security thing ?
Thanks
Regards
Le dim. 21 juil. 2024 à 17:35, Josh ***@***.***> a écrit :
Describe the bug
When a guest "Saves as", guest can save in the folder of the user who created the share.
To Reproduce
Steps to reproduce the behavior:
USER creates a folder and shares a link with write access.
GUEST enters the folder, creates an Opendocument sheet, and opens it via Nextcloud Richdocuments app, with CODE.
GUEST "Saves as" or ("Export") to /File.ods
Expected behavior
The "/" is related to the files of USER, not to the share.
GUEST should be restricted to writing in the shared folder only.
Screenshots
N/A
Client details:
Server details
Operating system:
Fedora
Web server:
Apache
Database:
Mariadb
PHP version:
8.3.8
Nextcloud version:
29.0.3
Version of the richdocuments app
8.4.3
Version of Collabora Online
COOLWSD version:
24.04.4.2 git hash: fbf97e9 (E)
Configuration of the richdocuments app
The text was updated successfully, but these errors were encountered: