Don't let a group's members share its calendars, address books or files
#146 stopped a group's members sharing its mailboxes on. The same shortcut lets them through everywhere else a group owns things: a member counts as the account's owner, so Calendar/set, AddressBook/set and FileNode/set skip the share check, and so does the WebDAV ACL method. Who has what a group owns is decided by who is in the group. For a member through a group only (is_group_member_only): - Calendar/set, AddressBook/set and FileNode/set refuse a shareWith change as forbidden, on create and update; for files at the top of the account too, not only inside a folder; - the DAV ACL method answers 403 on the group's calendars, address books and files; - myRights reports mayShare false (JmapRights::owner_rights), and the DAV current-user-privilege-set leaves out all and write-acl. Reading who something is shared with is unchanged, as in JMAP. Tests: a new jmap::group_share module has a member create with a share, create without one (and check myRights), share afterwards, and an outsider reach each kind; the WebDAV ACL test has a member try the ACL method on the group's folders; the IMAP ACL test now checks #146's SETACL refusal, which had no test of its own. jmap_tests, webdav_tests and imap_tests pass (RocksDB). specs/multi-account.md MA-D0.
This commit is contained in:
1 parent
5f6548bfdd
commit
58d2804278
12 files changed
+267
-4
No files matched your search
@@ -2,6 +2,8 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use crate::utils::{server::TestServer, webdav::GenerateTestDavResource};
|
||||
@@ -407,6 +409,40 @@ pub async fn test(test: &TestServer) {
|
||||
.with_status(StatusCode::NO_CONTENT);
|
||||
}
|
||||
|
||||
// inbuxa: MA-D0: Jane, a member of the Support group, can make a folder in
|
||||
// the group's account but can't share it on
|
||||
let member_client = test.account("[email protected]").webdav_client();
|
||||
let john_principal = format!(
|
||||
"{}/john%40example.com/",
|
||||
DavResourceName::Principal.base_path()
|
||||
);
|
||||
for resource_type in [
|
||||
DavResourceName::File,
|
||||
DavResourceName::Cal,
|
||||
DavResourceName::Card,
|
||||
] {
|
||||
let group_folder = format!(
|
||||
"{}/support%40example.com/group-folder/",
|
||||
resource_type.base_path()
|
||||
);
|
||||
member_client
|
||||
.request("MKCOL", &group_folder, "")
|
||||
.await
|
||||
.with_status(StatusCode::CREATED);
|
||||
member_client
|
||||
.acl(&group_folder, john_principal.as_str(), ["read"])
|
||||
.await
|
||||
.with_status(StatusCode::FORBIDDEN);
|
||||
member_client
|
||||
.request("DELETE", &group_folder, "")
|
||||
.await
|
||||
.with_status(StatusCode::NO_CONTENT);
|
||||
}
|
||||
// Reaching the group's calendars and address books made its defaults
|
||||
member_client
|
||||
.delete_default_containers_by_account("[email protected]")
|
||||
.await;
|
||||
|
||||
sharee_client.delete_default_containers().await;
|
||||
owner_client.delete_default_containers().await;
|
||||
test.assert_is_empty().await;
|
||||
|
||||
Reference in new issue
Block a user