Skip to content

Conversation

@rullzer
Copy link
Member

@rullzer rullzer commented Dec 4, 2018

If you disable the Allow username autocompletion in share dialog. If this is disabled the full username or email address needs to be entered. (share options)

Then we should also not allow enumeration on this endpoint.

Fixes #9058

Depends on:

@rullzer rullzer added the 3. to review Waiting for reviews label Dec 4, 2018
@rullzer rullzer added this to the Nextcloud 16 milestone Dec 4, 2018
@MorrisJobke
Copy link
Member

[x] #12813

Was merged.

Fixes #9058

If the option to autocomplete users is disabled. We also should not
enumerate the users on this endpoint.

Signed-off-by: Roeland Jago Douma <[email protected]>
@rullzer rullzer force-pushed the fix/9058/no_user_enumartion_if_disabled branch from 1538b07 to 58ca6b1 Compare December 4, 2018 14:33
Copy link
Member

@ChristophWurst ChristophWurst left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code looks good, change makes sense!

@MorrisJobke MorrisJobke mentioned this pull request Dec 5, 2018
12 tasks
@rullzer rullzer merged commit 8ddc0de into master Dec 5, 2018
@rullzer rullzer deleted the fix/9058/no_user_enumartion_if_disabled branch December 5, 2018 19:58
@rullzer
Copy link
Member Author

rullzer commented Dec 5, 2018

/backport to stable15

@backportbot-nextcloud
Copy link

backport to stable15 in #12856

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants