Commit graph

18218 commits

Author SHA1 Message Date
Carl Schwan
5b7b972882 Fix security issues when copying groupfolder with advanced ACL
Using advanced ACL, it is possible that an user has access to a
directory but not to a subdirectory, so the copying use
Common::copyFromStorage instead of Local::copyFromStorage.

Fix https://github.com/nextcloud/groupfolders/issues/1692

Signed-off-by: Carl Schwan <carl@carlschwan.eu>
2021-11-02 13:57:12 +00:00
Lukas Reschke
f53ae86efe Bump autoloader
Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-09-13 17:38:02 +02:00
Lukas Reschke
dcdc654bed Add database ratelimiting backend
In case no distributed memory cache is specified this adds
a database backend for ratelimit purposes.

Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-09-13 17:38:02 +02:00
Nextcloud bot
eb65d3d76b
[tx-robot] updated from transifex 2021-07-10 02:32:00 +00:00
Nextcloud bot
440aef0847
[tx-robot] updated from transifex 2021-07-09 02:26:53 +00:00
Nextcloud bot
d7f580d217
[tx-robot] updated from transifex 2021-07-08 02:27:17 +00:00
Nextcloud bot
4cf7372947
[tx-robot] updated from transifex 2021-07-06 02:26:30 +00:00
Nextcloud bot
6eb77e6380
[tx-robot] updated from transifex 2021-07-01 02:25:23 +00:00
Nextcloud bot
5dbe94d2fb
[tx-robot] updated from transifex 2021-06-28 02:25:40 +00:00
Nextcloud bot
b61dd6dc6a
[tx-robot] updated from transifex 2021-06-27 02:26:09 +00:00
Nextcloud bot
6689fe9722
[tx-robot] updated from transifex 2021-06-26 02:26:14 +00:00
Nextcloud bot
5b69b0a66d
[tx-robot] updated from transifex 2021-06-25 02:26:02 +00:00
Nextcloud bot
6ce6125ca0
[tx-robot] updated from transifex 2021-06-24 02:25:50 +00:00
Lukas Reschke
159762d54a
Merge pull request #27618 from nextcloud/backport/27610/stable19
[stable19] Throttle on public DAV endpoint
2021-06-23 18:50:09 +02:00
Lukas Reschke
9588fb0424 Update autoloader map
Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-06-23 15:06:30 +02:00
Lukas Reschke
6f23221efb Add newline to satisfy phpcs
Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-06-23 12:27:34 +02:00
Joas Schilling
0b443a7adf Send "429 Too Many Requests" in case of brute force protection
Signed-off-by: Joas Schilling <coding@schilljs.com>
2021-06-23 12:17:04 +02:00
blizzz
78a8bfe8ec
Merge pull request #27598 from nextcloud/backport/27596/stable19
[stable19] [stable20] Properly cleanup entries of WebAuthn on user deletion
2021-06-23 12:07:51 +02:00
Nextcloud bot
c15e1676e4
[tx-robot] updated from transifex 2021-06-23 02:26:47 +00:00
Lukas Reschke
ab605b7218 Remove throwing annotation
This class was just introduced in Nc 21.

Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-06-22 13:51:17 +00:00
Lukas Reschke
9f63ce182f Use execute instead of executeStatement
Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-06-22 13:51:16 +00:00
Morris Jobke
dba013f428 Properly cleanup entries of WebAuthn on user deletion
Signed-off-by: Morris Jobke <hey@morrisjobke.de>
2021-06-22 13:51:14 +00:00
Nextcloud bot
bbb6cb13f4
[tx-robot] updated from transifex 2021-06-22 02:27:29 +00:00
Nextcloud bot
b3ab4c4316
[tx-robot] updated from transifex 2021-06-20 02:27:33 +00:00
Nextcloud bot
8829a1d8c7
[tx-robot] updated from transifex 2021-06-19 02:46:48 +00:00
Nextcloud bot
a3062caf80
[tx-robot] updated from transifex 2021-06-18 02:27:33 +00:00
Nextcloud bot
32b1529f3f
[tx-robot] updated from transifex 2021-06-17 02:26:23 +00:00
Nextcloud bot
e13167bf24
[tx-robot] updated from transifex 2021-06-13 02:26:37 +00:00
Nextcloud bot
52c501c8a7
[tx-robot] updated from transifex 2021-06-12 02:27:29 +00:00
Julius Härtl
728e5ef966
Merge pull request #27307 from nextcloud/backport/27062/stable19
[stable19] properly use limit and offset for search in Jail wrapper
2021-06-09 08:10:27 +02:00
Nextcloud bot
ac4c7a345e
[tx-robot] updated from transifex 2021-06-09 02:26:46 +00:00
Nextcloud bot
497ace737a
[tx-robot] updated from transifex 2021-06-08 02:26:51 +00:00
Morris Jobke
6f0233b9ea
Merge pull request #27210 from nextcloud/backport/27199/stable19
[stable19] Use noreply@ as email address for share emails
2021-06-07 10:47:20 +02:00
Morris Jobke
a7fd0fc951
Merge pull request #27338 from nextcloud/backport/27329/stable19
[stable19] Propagate throttling on OCS response
2021-06-07 10:39:07 +02:00
Morris Jobke
3f9ccd68cd
Merge pull request #27361 from nextcloud/backport/27354/stable19
[stable19] Escape filename in Content-Disposition
2021-06-07 10:36:09 +02:00
Nextcloud bot
3f83ed8fc8
[tx-robot] updated from transifex 2021-06-07 02:25:40 +00:00
Nextcloud bot
1fd0f44ecd
[tx-robot] updated from transifex 2021-06-06 02:26:32 +00:00
Nextcloud bot
50a81509d7
[tx-robot] updated from transifex 2021-06-04 02:28:46 +00:00
Nextcloud bot
79f1f56f6d
[tx-robot] updated from transifex 2021-06-03 02:29:19 +00:00
Lukas Reschke
800edafce8 Escape filename in Content-Disposition
We should escape all occurences of ' and \ in here.

Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-06-02 19:21:52 +00:00
Lukas Reschke
1292bd90c9 Propagate throttling on OCS response
The BaseResponse converter did not take over any throttling state from the DataResponse.

Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
2021-06-01 19:46:43 +00:00
Robin Appelman
8246f097de properly use limit and offset for search in Jail wrapper
Signed-off-by: Robin Appelman <robin@icewind.nl>
2021-05-31 13:54:19 +00:00
Nextcloud bot
46932b98d9
[tx-robot] updated from transifex 2021-05-31 02:35:56 +00:00
Nextcloud bot
74477e97a0
[tx-robot] updated from transifex 2021-05-30 02:25:36 +00:00
Morris Jobke
5e8f5a0d85 Use noreply@ as email address for share emails
Fixes #26683

Before it used the instance name, which a) doesn't make sense to randomly guess email addresses and b) could contain characters that are not allowed in email addresses like spaces.

Signed-off-by: Morris Jobke <hey@morrisjobke.de>
2021-05-28 11:46:25 +00:00
Nextcloud bot
982186ec4a
[tx-robot] updated from transifex 2021-05-26 02:28:59 +00:00
Nextcloud bot
41c4d73c52
[tx-robot] updated from transifex 2021-05-25 02:27:49 +00:00
Nextcloud bot
299f78257f
[tx-robot] updated from transifex 2021-05-23 02:26:18 +00:00
Nextcloud bot
245ff80775
[tx-robot] updated from transifex 2021-05-22 02:27:46 +00:00
Morris Jobke
e7f2d3eaa0
Merge pull request #27041 from nextcloud/rullzer-patch-1
Use proper query method. No get yet on stable19
2021-05-21 09:09:41 +02:00