Browse Source

Prevent objectstore being set from client side

remotes/origin/notification-style
Robin McCorkell 10 years ago
parent
commit
63218ec098
  1. 10
      apps/files_external/controller/storagescontroller.php
  2. 8
      apps/files_external/service/storagesservice.php

10
apps/files_external/controller/storagescontroller.php

@ -138,6 +138,16 @@ abstract class StoragesController extends Controller {
);
}
if ($storage->getBackendOption('objectstore')) {
// objectstore must not be sent from client side
return new DataResponse(
array(
'message' => (string)$this->l10n->t('Objectstore forbidden')
),
Http::STATUS_UNPROCESSABLE_ENTITY
);
}
/** @var Backend */
$backend = $storage->getBackend();
/** @var AuthMechanism */

8
apps/files_external/service/storagesservice.php

@ -472,10 +472,14 @@ abstract class StoragesService {
if (!isset($allStorages[$id])) {
throw new NotFoundException('Storage with id "' . $id . '" not found');
}
$oldStorage = $allStorages[$id];
$allStorages[$id] = $updatedStorage;
// ensure objectstore is persistent
if ($objectstore = $oldStorage->getBackendOption('objectstore')) {
$updatedStorage->setBackendOption('objectstore', $objectstore);
}
$allStorages[$id] = $updatedStorage;
$this->writeConfig($allStorages);
$this->triggerChangeHooks($oldStorage, $updatedStorage);

Loading…
Cancel
Save