[Bug]: Duplicate file resolution blocked for share links
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 36.9k
- Forks
- 5.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 713
Description
⚠️ This issue respects the following points: ⚠️
- This is a bug, not a question or a configuration/webserver/proxy issue.
- This issue is not already reported on Github OR Nextcloud Community Forum (I've searched it).
- Nextcloud Server is up to date. See Maintenance and Release Schedule for supported versions.
- I agree to follow Nextcloud's Code of Conduct.
Bug description
If the recipient of a share link, having read permissions granted, attempts to resolve a duplicate file using the duplicate file conflict dialogue an error is triggered which states the action is blocked by access control. This is true for both share links and file request links.
Steps to reproduce
- Create share link for a folder
- Ensure Read permissions are granted on the share link
- Access share link as anonymous user
- Upload the same file twice which prompts the duplicate file dialogue
- Select the new file and click continue
Expected behavior
New file should overwrite existing file and user should receive confirmation message
Nextcloud Server version
34
Operating system
Debian/Ubuntu
PHP engine version
PHP 8.3
Web server
Apache (supported)
Database engine version
PostgreSQL
Is this bug present after an update or on a fresh install?
Fresh Nextcloud Server install
Are you using the Nextcloud Server Encryption module?
None
What user-backends are you using?
- Default user-backend (database)
- LDAP/ Active Directory
- SSO - SAML
- Other
Configuration report
## Server configuration detail
**Operating system:** Linux 5.15.0-161-generic #171-Ubuntu SMP Sat Oct 11 08:17:01 UTC 2025 x86_64
**Webserver:** Apache/2.4.67 (Unix) (fpm-fcgi)
**Database:** pgsql PostgreSQL 18.4 on x86_64-pc-linux-musl, compiled by gcc (Alpine 15.2.0) 15.2.0, 64-bit
**PHP version:** 8.3.31
Modules loaded: Core, date, libxml, openssl, pcre, sqlite3, zlib, ctype, curl, dom, fileinfo, filter, hash, iconv, json, mbstring, SPL, session, PDO, pdo_sqlite, bz2, posix, random, readline, Reflection, standard, SimpleXML, tokenizer, xml, xmlreader, xmlwriter, mysqlnd, cgi-fcgi, apcu, bcmath, Phar, exif, ftp, gd, gmp, igbinary, imagick, imap, intl, ldap, memcached, pcntl, pdo_pgsql, pgsql, redis, smbclient, sodium, sysvsem, zip, libsmbclient, Zend OPcache
**Nextcloud version:** 34.0.0 - 34.0.0.12
**Updated from an older Nextcloud/ownCloud or fresh install:**
**Where did you install Nextcloud from:** unknown
<details><summary>Signing status</summary>
[]
</details>
List of activated Apps
Enabled:
- activity: 7.0.0
- admin_audit: 1.24.0
- app_api: 34.0.0
- bruteforcesettings: 7.0.0
- calendar: 6.4.2
- circles: 34.0.0
- collectives: 4.4.1
- comments: 1.24.0
- contacts: 8.5.1
- contactsinteraction: 1.15.0
- dashboard: 7.14.0
- deck: 1.18.0
- federation: 1.24.0
- files_downloadlimit: 5.2.0-dev.0
- files_lock: 34.0.0
- files_pdfviewer: 7.0.0-dev.0
- files_reminders: 1.7.0
- files_sharing: 1.26.0
- files_trashbin: 1.24.0
- files_versions: 1.27.0
- firstrunwizard: 7.0.0-dev.0
- groupfolders: 22.0.0
- logreader: 7.0.0
- mail: 5.9.1
- nextcloud-aio: 0.8.0
- nextcloud_announcements: 6.0.0
- notes: 6.0.0
- notifications: 7.0.0-dev.1
- notify_push: 1.3.3
- office: 1.0.0
- password_policy: 6.0.0-dev.0
- photos: 7.0.0
- privacy: 6.0.0-dev.1
- recommendations: 7.0.0-dev.0
- related_resources: 5.0.0-dev.0
- richdocuments: 11.0.0
- serverinfo: 6.0.0
- sharebymail: 1.24.0
- spreed: 24.0.0
- support: 6.0.0
- survey_client: 6.0.0-dev.0
- systemtags: 1.24.0
- terms_of_service: 4.7.0
- text: 8.0.0
- twofactor_totp: 16.0.0
- updatenotification: 1.24.0
- user_status: 1.14.0
- weather_status: 1.14.0
- webhook_listeners: 1.6.0
- whiteboard: 1.5.9
Disabled:
- encryption
- files_external
- files_fulltextsearch
- fulltextsearch
- fulltextsearch_elasticsearch
- suspicious_login
- tasks
- twofactor_nextcloud_notification
- user_ldap
</details>
Nextcloud Signing status
No errors have been found
Nextcloud Logs
{"reqId":"KnFq1VngM9KVRdGXwZ7D","level":3,"time":"2026-07-23T07:46:35+00:00","remoteAddr":"69.9.132.189","user":"--","app":"no app in context","method":"PUT","url":"/public.php/dav/files/cmrzCNs4E5AfTYZ/Boss-DR1600.HEIC","scriptName":"/public.php","message":"Cannot set extra headers for non-existing file 'files/cmrzCNs4E5AfTYZ/Eric/Boss-DR1600 (2).HEIC'","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36","version":"34.0.0.12","data":[],"id":"6a61d1194ecba"}
{"reqId":"KnFq1VngM9KVRdGXwZ7D","level":2,"time":"2026-07-23T07:46:35+00:00","remoteAddr":"69.9.132.189","user":"--","app":"no app in context","method":"PUT","url":"/public.php/dav/files/cmrzCNs4E5AfTYZ/Boss-DR1600.HEIC","scriptName":"/public.php","message":"issue while running MetadataUpdate","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36","version":"34.0.0.12","exception":{"Exception":"OCP\\Files\\NotPermittedException","Message":"","Code":0,"Trace":[{"file":"/var/www/html/apps/photos/lib/Listener/ExifMetadataProvider.php","line":69,"function":"fopen","class":"OC\\Files\\Node\\File","type":"->","args":["rb"]},{"file":"/var/www/html/lib/private/EventDispatcher/ServiceEventListener.php","line":57,"function":"handle","class":"OCA\\Photos\\Listener\\ExifMetadataProvider","type":"->","args":[{"__class__":"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"}]},{"file":"/var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php","line":220,"function":"__invoke","class":"OC\\EventDispatcher\\ServiceEventListener","type":"->","args":[{"__class__":"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"},"OCP\\FilesMetadata\\Event\\MetadataLiveEvent",{"__class__":"Symfony\\Component\\EventDispatcher\\EventDispatcher"}]},{"file":"/var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php","line":56,"function":"callListeners","class":"Symfony\\Component\\EventDispatcher\\EventDispatcher","type":"->","args":[[{"__class__":"Closure"},{"__class__":"Closure"},{"__class__":"Closure"},{"__class__":"Closure"},{"__class__":"Closure"}],"OCP\\FilesMetadata\\Event\\MetadataLiveEvent",{"__class__":"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"}]},{"file":"/var/www/html/lib/private/EventDispatcher/EventDispatcher.php","line":73,"function":"dispatch","class":"Symfony\\Component\\EventDispatcher\\EventDispatcher","type":"->","args":[{"__class__":"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"},"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"]},{"file":"/var/www/html/lib/private/EventDispatcher/EventDispatcher.php","line":86,"function":"dispatch","class":"OC\\EventDispatcher\\EventDispatcher","type":"->","args":["OCP\\FilesMetadata\\Event\\MetadataLiveEvent",{"__class__":"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"}]},{"file":"/var/www/html/lib/private/FilesMetadata/FilesMetadataManager.php","line":101,"function":"dispatchTyped","class":"OC\\EventDispatcher\\EventDispatcher","type":"->","args":[{"__class__":"OCP\\FilesMetadata\\Event\\MetadataLiveEvent"}]},{"file":"/var/www/html/lib/private/FilesMetadata/Listener/MetadataUpdate.php","line":43,"function":"refreshMetadata","class":"OC\\FilesMetadata\\FilesMetadataManager","type":"->","args":[{"__class__":"OC\\Files\\Node\\File"}]},{"file":"/var/www/html/lib/private/EventDispatcher/ServiceEventListener.php","line":57,"function":"handle","class":"OC\\FilesMetadata\\Listener\\MetadataUpdate","type":"->","args":[{"__class__":"OCP\\Files\\Events\\Node\\NodeWrittenEvent"}]},{"file":"/var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php","line":220,"function":"__invoke","class":"OC\\EventDispatcher\\ServiceEventListener","type":"->","args":[{"__class__":"OCP\\Files\\Events\\Node\\NodeWrittenEvent"},"OCP\\Files\\Events\\Node\\NodeWrittenEvent",{"__class__":"Symfony\\Component\\EventDispatcher\\EventDispatcher"}]},{"file":"/var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php","line":56,"function":"callListeners","class":"Symfony\\Component\\EventDispatcher\\EventDispatcher","type":"->","args":[[{"__class__":"Closure"},{"__class__":"Closure"},{"__class__":"Closure"},{"__class__":"Closure"},{"__class__":"Closure"},"And 3 more entries, set log level to debug to see all entries"],"OCP\\Files\\Events\\Node\\NodeWrittenEvent",{"__class__":"OCP\\Files\\Events\\Node\\NodeWrittenEvent"}]},{"file":"/var/www/html/lib/private/EventDispatcher/EventDispatcher.php","line":73,"function":"dispatch","class":"Symfony\\Component\\EventDispatcher\\EventDispatcher","type":"->","args":[{"__class__":"OCP\\Files\\Events\\Node\\NodeWrittenEvent"},"OCP\\Files\\Events\\Node\\NodeWrittenEvent"]},{"file":"/var/www/html/lib/private/EventDispatcher/EventDispatcher.php","line":86,"function":"dispatch","class":"OC\\EventDispatcher\\EventDispatcher","type":"->","args":["OCP\\Files\\Events\\Node\\NodeWrittenEvent",{"__class__":"OCP\\Files\\Events\\Node\\NodeWrittenEvent"}]},{"file":"/var/www/html/lib/private/Files/Node/HookConnector.php","line":83,"function":"dispatchTyped","class":"OC\\EventDispatcher\\EventDispatcher","type":"->","args":[{"__class__":"OCP\\Files\\Events\\Node\\NodeWrittenEvent"}]},{"file":"/var/www/html/lib/private/legacy/OC_Hook.php","line":87,"function":"postWrite","class":"OC\\Files\\Node\\HookConnector","type":"->","args":[{"path":"/Documents/Eric/Eric/Boss-DR1600 (2).HEIC"}]},{"file":"/var/www/html/apps/dav/lib/Connector/Sabre/File.php","line":450,"function":"emit","class":"OC_Hook","type":"::","args":["OC_Filesystem","post_write",{"path":"/Documents/Eric/Eric/Boss-DR1600 (2).HEIC"}]},{"file":"/var/www/html/apps/dav/lib/Connector/Sabre/File.php","line":370,"function":"emitPostHooks","class":"OCA\\DAV\\Connector\\Sabre\\File","type":"->","args":[false]},{"file":"/var/www/html/apps/dav/lib/Connector/Sabre/Directory.php","line":127,"function":"put","class":"OCA\\DAV\\Connector\\Sabre\\File","type":"->","args":["*** sensitive parameters replaced ***"]},{"file":"/var/www/html/3rdparty/sabre/dav/lib/DAV/Server.php","line":1098,"function":"createFile","class":"OCA\\DAV\\Connector\\Sabre\\Directory","type":"->","args":["*** sensitive parameters replaced ***"]},{"file":"/var/www/html/3rdparty/sabre/dav/lib/DAV/CorePlugin.php","line":504,"function":"createFile","class":"Sabre\\DAV\\Server","type":"->","args":["*** sensitive parameters replaced ***"]},{"file":"/var/www/html/3rdparty/sabre/event/lib/WildcardEmitterTrait.php","line":89,"function":"httpPut","class":"Sabre\\DAV\\CorePlugin","type":"->","args":[{"__class__":"Sabre\\HTTP\\Request"},{"__class__":"Sabre\\HTTP\\Response"}]},{"file":"/var/www/html/3rdparty/sabre/dav/lib/DAV/Server.php","line":472,"function":"emit","class":"Sabre\\DAV\\Server","type":"->","args":["method:PUT",[{"__class__":"Sabre\\HTTP\\Request"},{"__class__":"Sabre\\HTTP\\Response"}]]},{"file":"/var/www/html/apps/dav/lib/Connector/Sabre/Server.php","line":215,"function":"invokeMethod","class":"Sabre\\DAV\\Server","type":"->","args":[{"__class__":"Sabre\\HTTP\\Request"},{"__class__":"Sabre\\HTTP\\Response"}]},{"file":"/var/www/html/apps/dav/appinfo/v2/publicremote.php","line":168,"function":"start","class":"OCA\\DAV\\Connector\\Sabre\\Server","type":"->","args":[]},{"file":"/var/www/html/public.php","line":90,"args":["/var/www/html/apps/dav/appinfo/v2/publicremote.php"],"function":"require_once"}],"File":"/var/www/html/lib/private/Files/Node/File.php","Line":104,"message":"issue while running MetadataUpdate","exception":"{\"class\":\"OCP\\Files\\NotPermittedException\",\"message\":\"\",\"code\":0,\"file\":\"/var/www/html/lib/private/Files/Node/File.php:104\",\"trace\":\"#0 /var/www/html/apps/photos/lib/Listener/ExifMetadataProvider.php(69): OC\\Files\\Node\\File->fopen('rb')\\n#1 /var/www/html/lib/private/EventDispatcher/ServiceEventListener.php(57): OCA\\Photos\\Listener\\ExifMetadataProvider->handle(Object(OCP\\FilesMetadata\\Event\\MetadataLiveEvent))\\n#2 /var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php(220): OC\\EventDispatcher\\ServiceEventListener->__invoke(Object(OCP\\FilesMetadata\\Event\\MetadataLiveEvent), 'OCP\\\\FilesMetada...', Object(Symfony\\Component\\EventDispatcher\\EventDispatcher))\\n#3 /var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php(56): Symfony\\Component\\EventDispatcher\\EventDispatcher->callListeners(Array, 'OCP\\\\FilesMetada...', Object(OCP\\FilesMetadata\\Event\\MetadataLiveEvent))\\n#4 /var/www/html/lib/private/EventDispatcher/EventDispatcher.php(73): Symfony\\Component\\EventDispatcher\\EventDispatcher->dispatch(Object(OCP\\FilesMetadata\\Event\\MetadataLiveEvent), 'OCP\\\\FilesMetada...')\\n#5 /var/www/html/lib/private/EventDispatcher/EventDispatcher.php(86): OC\\EventDispatcher\\EventDispatcher->dispatch('OCP\\\\FilesMetada...', Object(OCP\\FilesMetadata\\Event\\MetadataLiveEvent))\\n#6 /var/www/html/lib/private/FilesMetadata/FilesMetadataManager.php(101): OC\\EventDispatcher\\EventDispatcher->dispatchTyped(Object(OCP\\FilesMetadata\\Event\\MetadataLiveEvent))\\n#7 /var/www/html/lib/private/FilesMetadata/Listener/MetadataUpdate.php(43): OC\\FilesMetadata\\FilesMetadataManager->refreshMetadata(Object(OC\\Files\\Node\\File))\\n#8 /var/www/html/lib/private/EventDispatcher/ServiceEventListener.php(57): OC\\FilesMetadata\\Listener\\MetadataUpdate->handle(Object(OCP\\Files\\Events\\Node\\NodeWrittenEvent))\\n#9 /var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php(220): OC\\EventDispatcher\\ServiceEventListener->__invoke(Object(OCP\\Files\\Events\\Node\\NodeWrittenEvent), 'OCP\\\\Files\\\\Event...', Object(Symfony\\Component\\EventDispatcher\\EventDispatcher))\\n#10 /var/www/html/3rdparty/symfony/event-dispatcher/EventDispatcher.php(56): Symfony\\Component\\EventDispatcher\\EventDispatcher->callListeners(Array, 'OCP\\\\Files\\\\Event...', Object(OCP\\Files\\Events\\Node\\NodeWrittenEvent))\\n#11 /var/www/html/lib/private/EventDispatcher/EventDispatcher.php(73): Symfony\\Component\\EventDispatcher\\EventDispatcher->dispatch(Object(OCP\\Files\\Events\\Node\\NodeWrittenEvent), 'OCP\\\\Files\\\\Event...')\\n#12 /var/www/html/lib/private/EventDispatcher/EventDispatcher.php(86): OC\\EventDispatcher\\EventDispatcher->dispatch('OCP\\\\Files\\\\Event...', Object(OCP\\Files\\Events\\Node\\NodeWrittenEvent))\\n#13 /var/www/html/lib/private/Files/Node/HookConnector.php(83): OC\\EventDispatcher\\EventDispatcher->dispatchTyped(Object(OCP\\Files\\Events\\Node\\NodeWrittenEvent))\\n#14 /var/www/html/lib/private/legacy/OC_Hook.php(87): OC\\Files\\Node\\HookConnector->postWrite(Array)\\n#15 /var/www/html/apps/dav/lib/Connector/Sabre/File.php(450): OC_Hook::emit('OC_Filesystem', 'post_write', Array)\\n#16 /var/www/html/apps/dav/lib/Connector/Sabre/File.php(370): OCA\\DAV\\Connector\\Sabre\\File->emitPostHooks(false)\\n#17 /var/www/html/apps/dav/lib/Connector/Sabre/Directory.php(127): OCA\\DAV\\Connector\\Sabre\\File->put(Resource id #21)\\n#18 /var/www/html/3rdparty/sabre/dav/lib/DAV/Server.php(1098): OCA\\DAV\\Connector\\Sabre\\Directory->createFile('Boss-DR1600 (2)...', Resource id #21)\\n#19 /var/www/html/3rdparty/sabre/dav/lib/DAV/CorePlugin.php(504): Sabre\\DAV\\Server->createFile('files/cmrzCNs4E...', Resource id #21, NULL)\\n#20 /var/www/html/3rdparty/sabre/event/lib/WildcardEmitterTrait.php(89): Sabre\\DAV\\CorePlugin->httpPut(Object(Sabre\\HTTP\\Request), Object(Sabre\\HTTP\\Response))\\n#21 /var/www/html/3rdparty/sabre/dav/lib/DAV/Server.php(472): Sabre\\DAV\\Server->emit('method:PUT', Array)\\n#22 /var/www/html/apps/dav/lib/Connector/Sabre/Server.php(215): Sabre\\DAV\\Server->invokeMethod(Object(Sabre\\HTTP\\Request), Object(Sabre\\HTTP\\Response))\\n#23 /var/www/html/apps/dav/appinfo/v2/publicremote.php(168): OCA\\DAV\\Connector\\Sabre\\Server->start()\\n#24 /var/www/html/public.php(90): require_once('/var/www/html/a...')\\n#25 {main}\"}","CustomMessage":"issue while running MetadataUpdate"},"id":"6a61d1194ed0a"}
Additional info
This bug was found on a Nextcloud LTD - https://automationanywhere.ltd3.nextcloud.com/
Admin credentials here - https://cloud.nextcloud.com/apps/tables/#/view/131
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce the duplicate-file flow through the share link, then inspect apps/dav/lib/Connector/Sabre/File.php and apps/dav/lib/Connector/Sabre/Directory.php, starting at the PUT path shown in the trace. Compare the access-control handling for share links and file request links. Done means an anonymous recipient can overwrite the existing file and receives the expected confirmation without an access-control error.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- api, authorization, backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 50/100