Don't let a group's members share its mailboxes on
A group's members reach its mailbox through membership, which counts as owning the account, so every ACL check was skipped: on a scratch server a member gave an outsider read access to the group's Inbox with one Mailbox/set shareWith, with no administrator involved and nothing audited. Who is in a group is an administrator's decision. AccessToken::is_group_member_only names that case (in the account only through a group, without Impersonate). For such a member: - Mailbox/set with a shareWith change, on create or update, is refused as forbidden; - IMAP SETACL and DELETEACL answer NO [NOPERM]; - myRights reports mayShare false, and MYRIGHTS leaves out "a"; every other right stays. Administrators and the account itself are unchanged. The JMAP ACL test's group section now checks all three for a member and that the outsider still has nothing (specs/multi-account.md, MA-D0, G1). jmap_tests and imap_tests pass (RocksDB). The IMAP refusal has no test of its own yet; imap_tests passing shows the rest is unchanged.
This commit is contained in:
1 parent
d7bebd454d
commit
2d8728793c
5 files changed
+72
-4
No files matched your search
@@ -713,6 +713,35 @@ pub async fn test(test: &TestServer) {
|
||||
.await,
|
||||
);
|
||||
|
||||
// inbuxa: MA-D0: a member can't share the group's mailbox on, and isn't
|
||||
// told it may. Who is in a group is an administrator's decision.
|
||||
assert_forbidden(
|
||||
john_client
|
||||
.set_default_account_id(sales.id_string())
|
||||
.mailbox_update_acl(&inbox_id, bill.id_string(), [ACL::ReadItems])
|
||||
.await,
|
||||
);
|
||||
assert!(
|
||||
!john_client
|
||||
.set_default_account_id(sales.id_string())
|
||||
.mailbox_get(&inbox_id, [mailbox::Property::MyRights].into())
|
||||
.await
|
||||
.unwrap()
|
||||
.unwrap()
|
||||
.my_rights()
|
||||
.unwrap()
|
||||
.acl_list()
|
||||
.contains(&ACL::Administer)
|
||||
);
|
||||
bill_client.refresh_session().await.unwrap();
|
||||
assert!(bill_client.session().account(sales.id_string()).is_none());
|
||||
assert_forbidden(
|
||||
bill_client
|
||||
.set_default_account_id(sales.id_string())
|
||||
.email_get(&email_id, [Property::Subject].into())
|
||||
.await,
|
||||
);
|
||||
|
||||
// Remove John from the sales group
|
||||
admin
|
||||
.registry_update_object(
|
||||
|
||||
Reference in new issue
Block a user