Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

If a user belongs to a group that has not been set in the excluded groups from sharing, he can share files #20473

Closed
davitol opened this issue Nov 12, 2015 · 2 comments

Comments

@davitol
Copy link
Contributor

davitol commented Nov 12, 2015

Steps to reproduce

  1. Create a user that belongs to two groups
  2. Go to admin page
  3. Set one of the previous groups to be excluded from sharing
  4. Login with the user created and try to share a file

Expected behaviour

Proposal:
If a user belongs to a group that has been set in the excluded groups from sharing, he should not be able to share files (most restrictive condition)

Actual behaviour

If a user belongs to a group that has not been set in the excluded groups, he can share files

Server configuration

Operating system: ubuntu 14.04

Web server: apache 2.4.7

Database: mysql

PHP version: 5.5.9

**ownCloud version: ownCloud Enterprise Edition 8.2.1. (RC2)

Updated from an older ownCloud or fresh install: Fresh install

Are you using external storage, if yes which one: no;
Are you using encryption: no
Are you using an external user-backend, if yes which one: no

Client configuration

Browser: Firefox

screen shot 2015-11-12 at 11 02 14

@davitol davitol added this to the 9.1-next milestone Nov 12, 2015
@davitol davitol changed the title If a user belongs to a group that has not been set in the excluded groups for sharing, he can share files If a user belongs to a group that has not been set in the excluded groups from sharing, he can share files Nov 12, 2015
@davitol
Copy link
Contributor Author

davitol commented Nov 12, 2015

@blizzz

Another situation:
Using an Active Directory with nested groups allowed. User belongs to group1 and this group is included in group2 (nested). If group2 is added to 'Exclude groups from sharing', the user should not be able to share files, even if group1 is not included in the forbidden groups specifically

@rullzer rullzer removed this from the 9.1-next milestone Nov 14, 2015
@rullzer
Copy link
Contributor

rullzer commented Nov 14, 2015

Well that would be changeing behaviour and have unexpected result for people that rely on the current behaviour.

Anyway, this is a duplicate of #16346. So lets discuss there.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants