Skip to content

[stable33] fix(files_sharing): validate input in PublicPreviewController#getPreview - #61959

Closed
backportbot[bot] wants to merge 8 commits into
stable33from
backport/59253/stable33
Closed

[stable33] fix(files_sharing): validate input in PublicPreviewController#getPreview#61959
backportbot[bot] wants to merge 8 commits into
stable33from
backport/59253/stable33

Conversation

@backportbot

@backportbotbackportbotBot commented Jul 9, 2026

Copy link
Copy Markdown

Backport of #59253

Warning, This backport's changes differ from the original and might be incomplete ⚠️

Todo

  • Review and resolve any conflicts
  • Review and verify the backported changes
  • Remove all the empty commits
  • Amend HEAD commit to remove the line stating to skip CI

Learn more about backports at https://docs.nextcloud.com/server/stable/go.php?to=developer-backports.

mvanhornand others added 8 commits July 9, 2026 20:07
Return 400 Bad Request when the file parameter is empty and the shared
node is a folder, instead of passing the folder itself to getPreview
which triggers an internal server error.
Also rename the local variable to $fileNode to prevent the catch block
from calling getMimeType() on the original string parameter when
get() throws NotFoundException.
Fixes#59229
Signed-off-by: Matt Van Horn <mvanhorn@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
…variable naming
And slightly streamline the logic for clarity.
Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
…ler#getPreview edge cases
Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
… in tests
Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
…lean
Signed-off-by: Josh <josh.t.richards@gmail.com>
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
…bles
Addresses review feedback on PR #59253:
* Catch `NotPermittedException` from `$shareNode->get()` and return 403
FORBIDDEN instead of propagating an internal server error (per @kesselb
on line 133).
* Drop the unused `$e` capture from the existing `NotFoundException` and
`\InvalidArgumentException` catch blocks, using PHP 8.0 no-capture
syntax (per @kesselb on line 150).
* Add `testPreviewFolderSubfolderReturnsBadRequest` covering the branch
where a folder share resolves `$file` to a subfolder and must return
400 (per @Copilot on line 136).
Signed-off-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
fix(files_sharing): return 403 on NotPermittedException and sync openapi
[skip ci]
@backportbot
backportbotBot requested a review from kesselbJuly 9, 2026 20:07
@backportbotbackportbotBot added this to the Nextcloud 33.0.7 milestone Jul 9, 2026
@kesselbkesselb closed this Jul 9, 2026
@kesselb
kesselb deleted the backport/59253/stable33 branch July 9, 2026 20:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@kesselb@mvanhorn@joshtrichards