nextcloud / nextcloud/server

Files sharing should show a clearer message when share creation is rate limited

Open Beginner friendly
#60,729 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

1. to develop enhancement feature: sharing papercut
Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

Steps to reproduce
  1. Sign in as a normal user.
  2. Open the sharing dialog for a file or folder.
  3. Create public link shares repeatedly until the ShareAPIController::createShare user rate limit is reached.
  4. Try to create another share, either on the same item or another item.
Expected behavior

The UI should explain that share creation is temporarily rate limited, for example:

Share creation is temporarily rate limited. Please wait a few minutes before creating more shares.

Ideally it should also make clear that this is a per-user/time-window creation limit, not a per-file or per-folder share limit.

Actual behavior

The request returns HTTP 429 / Too Many Requests, but the Files sharing UI does not give enough context for admins or users to understand why share creation stopped. This can be mistaken for a per-file share limit or a broken sharing dialog.

Technical context

OCA\Files_Sharing\Controller\ShareAPIController::createShare is intentionally protected with:

#[UserRateLimit(limit: 20, period: 600)]

When the limit is exceeded, RateLimitingMiddleware returns a generic 429 response. The frontend currently falls back to the response metadata, if available, or a generic share creation error.

Suggested improvement

Handle 429 responses from the share creation request in the Files sharing frontend and show a dedicated translated message. This should avoid implying that the file/folder has reached a permanent sharing limit.

Notes

This issue is only about improving the user-facing error message. It does not request changing the existing rate limit.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the Files sharing frontend's share creation request and compare its handling with ShareAPIController::createShare and the generic 429 response from RateLimitingMiddleware. Add a translated, dedicated message for HTTP 429 that explains the temporary per-user creation limit, then verify other share-creation errors still use their existing handling.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, php
Domain
api, frontend
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.