Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trash: not isolated by user #178

Closed
chibenwa opened this issue Aug 28, 2023 · 2 comments
Closed

Trash: not isolated by user #178

chibenwa opened this issue Aug 28, 2023 · 2 comments
Labels
bug Something isn't working

Comments

@chibenwa
Copy link
Member

Describe the bug

User A deletes a file in a private space
User B goes in the trash and sees it

This cause a major breach in user data isolation and is a major security vulnerability.

Expected behavior

User B can see the file in the trash ONLY if he has access to the file BEFORE it gets deleted.

Screenshots

@guimard trash:

Tdrive

The file "bte-private" was in my local space.

Note that apparently access control works for files in shared space with restricted rights.

@chibenwa chibenwa added the bug Something isn't working label Aug 28, 2023
@shepilov
Copy link
Member

Thank you for the bug report, @chibenwa !
yes, we'll need to fix it asap.
We've created personal space, but trash is still shared

@shepilov
Copy link
Member

#179 US for separate trash

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants