From 8613dd77368ddd299b1335926bbb3c7e369f3d63 Mon Sep 17 00:00:00 2001 From: Robin Appelman Date: Mon, 4 May 2026 18:00:52 +0200 Subject: [PATCH 1/2] fix: don't tell the remote their token is lower Signed-off-by: Robin Appelman --- apps/federation/lib/Controller/OCSAuthAPIController.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/federation/lib/Controller/OCSAuthAPIController.php b/apps/federation/lib/Controller/OCSAuthAPIController.php index be4466919f6..5a2bca4c875 100644 --- a/apps/federation/lib/Controller/OCSAuthAPIController.php +++ b/apps/federation/lib/Controller/OCSAuthAPIController.php @@ -126,7 +126,7 @@ class OCSAuthAPIController extends OCSController { 'remote server (' . $url . ') presented lower token. We will initiate the exchange of the shared secret.', ['app' => 'federation'] ); - throw new OCSForbiddenException(); + return new DataResponse(); } $this->jobList->add( From 17ad1e7e9ed99c874626c4cb550a163caddacd16 Mon Sep 17 00:00:00 2001 From: Robin Appelman Date: Tue, 19 May 2026 19:39:05 +0200 Subject: [PATCH 2/2] test: adjust tests Signed-off-by: Robin Appelman --- .../federation/tests/Controller/OCSAuthAPIControllerTest.php | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/apps/federation/tests/Controller/OCSAuthAPIControllerTest.php b/apps/federation/tests/Controller/OCSAuthAPIControllerTest.php index 8c9b9b62566..4cfda194944 100644 --- a/apps/federation/tests/Controller/OCSAuthAPIControllerTest.php +++ b/apps/federation/tests/Controller/OCSAuthAPIControllerTest.php @@ -125,9 +125,9 @@ class OCSAuthAPIControllerTest extends TestCase { try { $this->ocsAuthApi->requestSharedSecret($url, $token); - $this->assertTrue($ok); + $this->assertTrue($isTrustedServer); } catch (OCSForbiddenException $e) { - $this->assertFalse($ok); + $this->assertFalse($isTrustedServer); } } @@ -183,7 +183,6 @@ class OCSAuthAPIControllerTest extends TestCase { try { $result = $ocsAuthApi->getSharedSecret($url, $token); - $this->assertTrue($ok); $data = $result->getData(); $this->assertSame('secret', $data['sharedSecret']); } catch (OCSForbiddenException $e) {