Skip to content

admin have no special rights on users' entries - #39895

Merged
skjnldsv merged 1 commit into
masterfrom
fix/noid/revoke-admin-overwrite
Sep 5, 2023
Merged

admin have no special rights on users' entries#39895
skjnldsv merged 1 commit into
masterfrom
fix/noid/revoke-admin-overwrite

Conversation

@ArtificialOwl

@ArtificialOwlArtificialOwl commented Aug 15, 2023

Copy link
Copy Markdown
Member

remove admin's right to modify users' external filesystem configuration.

Comment threadapps/files_external/lib/Controller/AjaxController.php Fixed
@szaimenszaimen added the 3. to review Waiting for reviews label Aug 16, 2023
@szaimenszaimen added this to the Nextcloud 28 milestone Aug 16, 2023
@ArtificialOwl
ArtificialOwlforce-pushed the fix/noid/revoke-admin-overwrite branch from 680b42e to fb2d29eCompareAugust 16, 2023 14:31
@ArtificialOwl

Copy link
Copy Markdown
MemberAuthor

failed test are not related

@ArtificialOwl
ArtificialOwlforce-pushed the fix/noid/revoke-admin-overwrite branch 3 times, most recently from fd40401 to 40584f1CompareAugust 18, 2023 11:13

// Non-admins can only edit their own credentials
$allowedToEdit = ($this->groupManager->isAdmin($currentUser->getUID()) || $currentUser->getUID() === $uid);
$allowedToEdit = ($currentUser->getUID() === $uid);

Check notice

Code scanning / Psalm

PossiblyNullReference

Cannot call method getUID on possibly null value
@ArtificialOwl

Copy link
Copy Markdown
MemberAuthor

/backport to stable27

@ArtificialOwl

Copy link
Copy Markdown
MemberAuthor

/backport to stable26

public function testSaveGlobalCredentialsAsNormalUserForSelf() {
$user = $this->createMock(IUser::class);
$user
->expects($this->exactly(2))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm in favor of just removing these count checks unless the number of times something is called is actually relevant to the test

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! and I thought I was the only one

@ArtificialOwl
ArtificialOwlforce-pushed the fix/noid/revoke-admin-overwrite branch 3 times, most recently from 2c1db9d to 6607388CompareAugust 31, 2023 20:27
@ArtificialOwl
ArtificialOwlforce-pushed the fix/noid/revoke-admin-overwrite branch from 6607388 to 1275bdfCompareAugust 31, 2023 21:55
@ArtificialOwl
ArtificialOwlforce-pushed the fix/noid/revoke-admin-overwrite branch from 1275bdf to 435f475CompareSeptember 1, 2023 09:23
Signed-off-by: Maxence Lange <maxence@artificial-owl.com>
@skjnldsv
skjnldsvforce-pushed the fix/noid/revoke-admin-overwrite branch from 435f475 to e55087bCompareSeptember 1, 2023 18:14
@skjnldsvskjnldsv added 4. to release Ready to be released and/or waiting for tests to finish and removed 3. to review Waiting for reviews labels Sep 1, 2023
@skjnldsv
skjnldsv merged commit 2018c72 into masterSep 5, 2023
@skjnldsv
skjnldsv deleted the fix/noid/revoke-admin-overwrite branch September 5, 2023 12:52
@backportbot-nextcloud

Copy link
Copy Markdown

The backport to stable26 failed. Please do this backport manually.

# Switch to the target branch and update it
git checkout stable26
git pull origin stable26
# Create the new backport branch
git checkout -b fix/foo-stable26
# Cherry pick the change from the commit sha1 of the change against the default branch# This might cause conflicts. Resolve them.
git cherry-pick abc123
# Push the cherry pick commit to the remote repository and open a pull request
git push origin fix/foo-stable26

More info at https://docs.nextcloud.com/server/latest/developer_manual/getting_started/development_process.html#manual-backport

@ArtificialOwl

Copy link
Copy Markdown
MemberAuthor

/backport to stable25

@AndyScherzinger

Copy link
Copy Markdown
Member

/backport to stable26

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4. to releaseReady to be released and/or waiting for tests to finishfeature: external storage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@ArtificialOwl@AndyScherzinger@icewind1991@github-advanced-security@joshtrichards@skjnldsv@szaimen