Skip to content

[QA] guests have access to customgroups without whitelisting #516

@jnweiger

Description

@jnweiger

Seen with core 10.11.0-beta.2 (and rc.1) while testing owncloud/core#40257
guests 0.11.0
customgroups 0.6.2 and also 0.7.0

Follow the reproducer steps in the 'How has this been tested`section:

  • Enable customgroups. Make sure its not listed as whitelisted apps in guest configuration.
    • the guests whitelist under Settings -> Sharing is: [settings,avatar,files_external,files_trashbin,files_versions,files_sharing,files_texteditor,activity,firstrunwizard,gallery,notifications,password_policy,oauth2,files_pdfviewer,files_mediaviewer,richdocuments,onlyoffice,wopi,oco_selfservice,twofactor_totp]
  • As guest user navigate to the settings page.
  • The settings page should not show customgroups. And it does not.
    • ⛔ guest user sees customgrous and can create customgroups

image
image

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions