nextcloud / nextcloud/logreader

*Download logs* shown to sub admin, results in unhandled 403

Open
#1,350 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

1. to develop bug
Dominant language
JavaScript
Stars
69
Forks
30
Avg merge
10h 28m
Merged PRs (30d)
57

Description

Steps to reproduce
  1. Set up nextcloud with sub admins
  2. Log in as sub admin
  3. Open the logging settings
  4. See and click Download logs
Expected behaviour

Either I don't see the button or it works

Actual behaviour

The button is clickable and a XHR to /settings/admin/log/download is sent. It results in a HTTP 403 with no UI or console handling.

Server configuration

Operating system:

Web server:

Database:

PHP version:

Nextcloud version: 30

Where did you install Nextcloud from:

List of activated apps:

If you have access to your command line run e.g.:
sudo -u www-data php occ app:list
from within your Nextcloud installation folder

Nextcloud configuration:

If you have access to your command line run e.g.:
sudo -u www-data php occ config:list system
from within your Nextcloud installation folder

or

Insert your config.php content here
Make sure to remove all sensitive content such as passwords. (e.g. database password, passwordsalt, secret, smtp password, …)
Client configuration

Browser:

Operating system:

Logs
Nextcloud log (data/owncloud.log)
Insert your Nextcloud log here
Browser log
Insert your browser log here, this could for example include:

a) The javascript console log
b) The network log
c) ...

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the logging settings UI and the XHR endpoint /settings/admin/log/download described in the report. Reproduce with a sub admin, then trace the button and request handling; done means the button is hidden for unauthorized users or the HTTP 403 receives appropriate UI handling.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
authorization, frontend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.