Browse Source
Check share attributes on preview endpoints
Signed-off-by: Julius Härtl <jus@bitgrid.net>
pull/34788/head
Julius Härtl
4 years ago
No known key found for this signature in database
GPG Key ID: 4C614C6ED2CDE6DF
3 changed files with
30 additions and
0 deletions
-
apps/files_sharing/lib/Controller/PublicPreviewController.php
-
core/Controller/PreviewController.php
-
tests/Core/Controller/PreviewControllerTest.php
|
|
|
@ -109,6 +109,11 @@ class PublicPreviewController extends PublicShareController { |
|
|
|
return new DataResponse([], Http::STATUS_FORBIDDEN); |
|
|
|
} |
|
|
|
|
|
|
|
$attributes = $share->getAttributes(); |
|
|
|
if ($attributes !== null && $attributes->getAttribute('permissions', 'download') === false) { |
|
|
|
return new DataResponse([], Http::STATUS_FORBIDDEN); |
|
|
|
} |
|
|
|
|
|
|
|
try { |
|
|
|
$node = $share->getNode(); |
|
|
|
if ($node instanceof Folder) { |
|
|
|
@ -159,6 +164,11 @@ class PublicPreviewController extends PublicShareController { |
|
|
|
return new DataResponse([], Http::STATUS_FORBIDDEN); |
|
|
|
} |
|
|
|
|
|
|
|
$attributes = $share->getAttributes(); |
|
|
|
if ($attributes !== null && $attributes->getAttribute('permissions', 'download') === false) { |
|
|
|
return new DataResponse([], Http::STATUS_FORBIDDEN); |
|
|
|
} |
|
|
|
|
|
|
|
try { |
|
|
|
$node = $share->getNode(); |
|
|
|
if ($node instanceof Folder) { |
|
|
|
|
|
|
|
@ -27,6 +27,7 @@ declare(strict_types=1); |
|
|
|
*/ |
|
|
|
namespace OC\Core\Controller; |
|
|
|
|
|
|
|
use OCA\Files_Sharing\SharedStorage; |
|
|
|
use OCP\AppFramework\Controller; |
|
|
|
use OCP\AppFramework\Http; |
|
|
|
use OCP\AppFramework\Http\DataResponse; |
|
|
|
@ -129,6 +130,16 @@ class PreviewController extends Controller { |
|
|
|
return new DataResponse([], Http::STATUS_FORBIDDEN); |
|
|
|
} |
|
|
|
|
|
|
|
$storage = $node->getStorage(); |
|
|
|
if ($storage->instanceOfStorage(SharedStorage::class)) { |
|
|
|
/** @var SharedStorage $storage */ |
|
|
|
$share = $storage->getShare(); |
|
|
|
$attributes = $share->getAttributes(); |
|
|
|
if ($attributes !== null && $attributes->getAttribute('permissions', 'download') === false) { |
|
|
|
return new DataResponse([], Http::STATUS_FORBIDDEN); |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
try { |
|
|
|
$f = $this->preview->getPreview($node, $x, $y, !$a, $mode); |
|
|
|
$response = new FileDisplayResponse($f, Http::STATUS_OK, [ |
|
|
|
|
|
|
|
@ -32,6 +32,7 @@ use OCP\Files\Folder; |
|
|
|
use OCP\Files\IRootFolder; |
|
|
|
use OCP\Files\NotFoundException; |
|
|
|
use OCP\Files\SimpleFS\ISimpleFile; |
|
|
|
use OCP\Files\Storage\IStorage; |
|
|
|
use OCP\IPreview; |
|
|
|
use OCP\IRequest; |
|
|
|
|
|
|
|
@ -176,6 +177,10 @@ class PreviewControllerTest extends \Test\TestCase { |
|
|
|
->with($this->equalTo('file')) |
|
|
|
->willReturn($file); |
|
|
|
|
|
|
|
$storage = $this->createMock(IStorage::class); |
|
|
|
$file->method('getStorage') |
|
|
|
->willReturn($storage); |
|
|
|
|
|
|
|
$this->previewManager->method('isAvailable') |
|
|
|
->with($this->equalTo($file)) |
|
|
|
->willReturn(true); |
|
|
|
@ -211,6 +216,10 @@ class PreviewControllerTest extends \Test\TestCase { |
|
|
|
$file->method('isReadable') |
|
|
|
->willReturn(true); |
|
|
|
|
|
|
|
$storage = $this->createMock(IStorage::class); |
|
|
|
$file->method('getStorage') |
|
|
|
->willReturn($storage); |
|
|
|
|
|
|
|
$preview = $this->createMock(ISimpleFile::class); |
|
|
|
$preview->method('getName')->willReturn('my name'); |
|
|
|
$preview->method('getMTime')->willReturn(42); |
|
|
|
|