Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sharing permission issue #22739

Closed
MorrisJobke opened this issue Feb 29, 2016 · 4 comments
Closed

Sharing permission issue #22739

MorrisJobke opened this issue Feb 29, 2016 · 4 comments

Comments

@MorrisJobke
Copy link
Contributor

Steps to reproduce

  1. user0, user1, user2 exist
  2. user0 shares folder A to user1(read-write) and user2 (read-only)
  3. user1 logs in and open the sidebar for received share A
  4. user0 removes the "can edit" permission for user1
  5. user1 (didn't refresh the browser) could still give user2 the "can edit" permission

note: after a refresh user1 couldn't see the "can edit" permission - so this seems to be possible from the API only and seems to be not properly checked.

Expected behavior

  • user1 could not do 5.

Actual behavior

  • user1 could do 5.

current master

Quite critical - cc @rullzer @PVince81 @LukasReschke

@MorrisJobke MorrisJobke added this to the 9.0.1-next-maintenance milestone Feb 29, 2016
@MorrisJobke
Copy link
Contributor Author

@cmonteroluque @PVince81 I put this into 9.0.1, but given that this is kind of critical I would be more than happy to have this solved in 9.0.

@MorrisJobke
Copy link
Contributor Author

Initial share setup (read mjob as user0) - after step 3:

bildschirmfoto 2016-02-29 um 18 27 10

@rullzer
Copy link
Contributor

rullzer commented Feb 29, 2016

Duplicate of #22675

@lock
Copy link

lock bot commented Aug 6, 2019

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@lock lock bot locked as resolved and limited conversation to collaborators Aug 6, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants