8000 [QA] guests have access to customgroups without whitelisting · Issue #516 · owncloud/guests · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
[QA] guests have access to customgroups without whitelisting #516
Open
@jnweiger

Description

@jnweiger

Seen with core 10.11.0-beta.2 (and rc.1) while testing owncloud/core#40257
guests 0.11.0
customgroups 0.6.2 and also 0.7.0

Follow the reproducer steps in the 'How has this been tested`section:

  • Enable customgroups. Make sure its not listed as whitelisted apps in guest configuration.
    • the guests whitelist under Settings -> Sharing is: [settings,avatar,files_external,files_trashbin,files_versions,files_sharing,files_texteditor,activity,firstrunwizard,gallery,notifications,password_policy,oauth2,files_pdfviewer,files_mediaviewer,richdocuments,onlyoffice,wopi,oco_selfservice,twofactor_totp]
  • As guest user navigate to the settings page.
  • The settings page should not show customgroups. And it does not.
    • ⛔ guest user sees customgrous and can create customgroups

image
image

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    0