owncloud / owncloud/core

[QA] folder shared with secure-view exposes PNG and JPG files

Open
#38,884 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

QA:team
Dominant language
PHP
Stars
8.8k
Forks
2.1k
Avg merge
20h 7m
Merged PRs (30d)
41

Description

seen with server 10.7.0

  • admin enables secure view as default sharing option.
  • user2 shares folder "user2-Photos" with user1.
    image

  • user1 sees
    image

Expected behaviour: according to documentation, JPG and PNG files should not be visible to user1 at all.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the scenario on server 10.7.0: enable secure view as the default sharing option, share the “user2-Photos” folder, and inspect what user1 can see. Compare the result with the secure-view documentation, focusing on why PNG and JPG files remain visible; done means those files are no longer exposed to user1.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authorization, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.