Don't let a group's members share its calendars, address books or files
#146 stopped a group's members sharing its mailboxes on. The same shortcut lets them through everywhere else a group owns things: a member counts as the account's owner, so Calendar/set, AddressBook/set and FileNode/set skip the share check, and so does the WebDAV ACL method. Who has what a group owns is decided by who is in the group. For a member through a group only (is_group_member_only): - Calendar/set, AddressBook/set and FileNode/set refuse a shareWith change as forbidden, on create and update; for files at the top of the account too, not only inside a folder; - the DAV ACL method answers 403 on the group's calendars, address books and files; - myRights reports mayShare false (JmapRights::owner_rights), and the DAV current-user-privilege-set leaves out all and write-acl. Reading who something is shared with is unchanged, as in JMAP. Tests: a new jmap::group_share module has a member create with a share, create without one (and check myRights), share afterwards, and an outsider reach each kind; the WebDAV ACL test has a member try the ACL method on the group's folders; the IMAP ACL test now checks #146's SETACL refusal, which had no test of its own. jmap_tests, webdav_tests and imap_tests pass (RocksDB). specs/multi-account.md MA-D0.
This commit is contained in:
1 parent
5f6548bfdd
commit
58d2804278
12 files changed
+267
-4
No files matched your search
@@ -250,6 +250,16 @@ impl FileNodeSet for Server {
|
||||
},
|
||||
};
|
||||
|
||||
// inbuxa: MA-D0: a group's members don't share what it owns on,
|
||||
// at the top of its files as anywhere else
|
||||
if has_acl_changes && access_token.is_group_member_only(account_id) {
|
||||
response.not_created.append(
|
||||
id,
|
||||
SetError::forbidden().with_description("This belongs to a group. Only an administrator can change who has it."),
|
||||
);
|
||||
continue 'create;
|
||||
}
|
||||
|
||||
// Inherit ACLs from parent
|
||||
if file_node.parent_id > 0 {
|
||||
let parent_id = file_node.parent_id - 1;
|
||||
@@ -509,6 +519,14 @@ impl FileNodeSet for Server {
|
||||
continue 'update;
|
||||
}
|
||||
}
|
||||
// inbuxa: MA-D0: a group's members don't share what it owns on.
|
||||
if has_acl_changes && access_token.is_group_member_only(account_id) {
|
||||
response.not_updated.append(
|
||||
id,
|
||||
SetError::forbidden().with_description("This belongs to a group. Only an administrator can change who has it."),
|
||||
);
|
||||
continue 'update;
|
||||
}
|
||||
if has_acl_changes {
|
||||
if let Err(err) = self.acl_validate(account_id, &new_file_node.acls).await {
|
||||
response.not_updated.append(id, err.into());
|
||||
|
||||
Reference in new issue
Block a user