You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We encountered a situation that a user can take away rights from another user in a group folder unjustly just by sharing contents back with lower rights.
Steps to reproduce
"Office" group has a group folder named "Shared Externally". Each member of "Office" group can Write, Share, Delete in this group folder.
This group folder has subfolders. Each subfolder is shared from a "office" group service user with another (different) user group. For this example we call the other group "Committee A".
The group "Committee A" have received the share with right to write and delete, but not to share further on.
One person from the "Office" group is a member of both, "Office" and "Committee A" group. (So s/he sees the group folder in its original hierarchy and additionally also on root level as a received share).
For a public event, this office person wants to share one document from the "Committee A" subfolder with an open link.
The share seems to be created without problems. But when anyone from outside uses the link, Nextcloud says that the document was not found. When an office person who is not group member of "Committee A" creates the link, it is available.
Expected behaviour
Group folder rights should be regarded higher than rights that come with share-receiving.
A user that is member of a group with full rights for a group folder should keep the rights, even if someone shares content of a subfolder again.
Actual behaviour
The office group user as mentioned in 1. loses rights, just because someone shared the same content back with lower rights.
Server configuration
Nextcloud version:
Nextcloud Hub II (23.0.4) with all updates
Group folders version:
11.1.2
Are you using external storage, if yes which one:
No
Are you using encryption: yes/no
No
Client configuration
Browser:
Any
The text was updated successfully, but these errors were encountered:
I can reproduce this issue on NC24rc3 with groupfolders 12beta1.
Sharing of files/folders within a groupfolder should work, even if the sharing user itself got a share of this groupfolder without sharing permissions.
We encountered a situation that a user can take away rights from another user in a group folder unjustly just by sharing contents back with lower rights.
Steps to reproduce
Expected behaviour
Group folder rights should be regarded higher than rights that come with share-receiving.
A user that is member of a group with full rights for a group folder should keep the rights, even if someone shares content of a subfolder again.
Actual behaviour
The office group user as mentioned in 1. loses rights, just because someone shared the same content back with lower rights.
Server configuration
Nextcloud version:
Nextcloud Hub II (23.0.4) with all updates
Group folders version:
11.1.2
Are you using external storage, if yes which one:
No
Are you using encryption: yes/no
No
Client configuration
Browser:
Any
The text was updated successfully, but these errors were encountered: