[Bug]: WebDAV TypeError (HTTP 500) in Directory::getNodeForPath when an ancestor is hidden by a Team folders ACL (Directory.php:571)
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 76/100
Línea de trabajo
Empieza en apps/dav/lib/Connector/Sabre/Directory.php, alrededor de la línea 571 de getNodeForPath(), y sigue cómo se gestionan los resultados de getFileInfo() de los directorios antecesores; el informe indica que puede devolver false antes del constructor de Directory. Revisa las pruebas relacionadas con esta ruta y añade cobertura para un antecesor ilegible. El trabajo estará terminado cuando la solicitud ya no produzca un TypeError/HTTP 500 y el comportamiento coincida con la respuesta prevista de no encontrado o acceso concedido.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Bug description
A WebDAV request for a folder whose parent is not readable to the user returns HTTP 500 (TypeError) instead of a clean response, when the parent is hidden by a Team folders (groupfolders) ACL rule.
OCA\DAV\Connector\Sabre\Directory::getNodeForPath() walks up the ancestors to check that each one is readable (added in #54441, "to keep ACL checks working in files_accesscontrol"):
// apps/dav/lib/Connector/Sabre/Directory.php, v34.0.4, lines 569-571
$info = $this->fileView->getFileInfo($scanPath, false);
$directory = new Directory($this->fileView, $info, $this->tree, $this->shareManager);
$readable = $directory->getNode()->isReadable();
For an ancestor that a groupfolders ACL makes unreadable, View::getFileInfo() returns false, not an unreadable FileInfo. The false reaches the Directory constructor unchecked, which throws:
TypeError: OCA\DAV\Connector\Sabre\Directory::__construct(): Argument #2 ($info) must be of type OCP\Files\FileInfo,
false given, called in /var/www/html/apps/dav/lib/Connector/Sabre/Directory.php on line 571
#00 OCA\DAV\Connector\Sabre\Directory->__construct() apps/dav/lib/Connector/Sabre/Directory.php:571
#01 OCA\DAV\Connector\Sabre\Directory->getNodeForPath() 3rdparty/sabre/dav/lib/DAV/Tree.php:86
#02 Sabre\DAV\Tree->getNodeForPath() 3rdparty/sabre/dav/lib/DAV/Server.php:971
#03 Sabre\DAV\Server->getPropertiesIteratorForPath() 3rdparty/sabre/dav/lib/DAV/Server.php:1664
#04 Sabre\DAV\Server->writeMultiStatus() 3rdparty/sabre/dav/lib/DAV/Server.php:1649
#05 Sabre\DAV\Server->generateMultiStatus() 3rdparty/sabre/dav/lib/DAV/CorePlugin.php:346
#06 Sabre\DAV\CorePlugin->httpPropFind() 3rdparty/sabre/event/lib/WildcardEmitterTrait.php:89
#07 Sabre\DAV\Server->emit() 3rdparty/sabre/dav/lib/DAV/Server.php:472
#08 Sabre\DAV\Server->invokeMethod() apps/dav/lib/Connector/Sabre/Server.php:215
#09 OCA\DAV\Connector\Sabre\Server->start() apps/dav/lib/Server.php:434
#10 OCA\DAV\Server->exec() apps/dav/appinfo/v2/remote.php:25
#11 require_once() remote.php:152
Uploads fail the same way. A PUT into the folder reaches the same line through OCA\DAV\Upload\ChunkingV2Plugin->beforePut() → prepareUpload() (ChunkingV2Plugin.php:171 / 342) → Tree->getNodeForPath().
This also blocks the legitimate case
This isn't only a configuration that is "unsupported by design":
- The ACL engine grants the access.
occ groupfolders:permissions <id> --test --user alice Restricted/alicereports+read, +write, +create, +delete, +share, and the web UI / ACL model let admins configure exactly this. Users with a valid grant get a server error instead of either their data or a clean denial. Desktop clients see a 500, not a 403/404, so they can't tell "no access" from "server broken". - The same unguarded call has another trigger with no ACL involved. Groupfolders trashbin entries over WebDAV hit it too: nextcloud/groupfolders#4984 (same TypeError, same
getNodeForPathchain, NC 33.0.7 / groupfolders 21.0.13, open). Any path wheregetFileInfo()returnsfalsefor an ancestor turns into a 500.
Whatever the intended outcome is (207 because the ACL grants read, or 404 because the parent is unreadable, as the loop's NotFound suggests), a TypeError/500 shouldn't be the answer. A minimal fix would treat $info === false like an unreadable ancestor and throw NotFound.
Steps to reproduce
- Nextcloud 34.0.4 with Team folders 22.0.6 (
groupfolders/acl-inherit-per-userat its defaultfalse;truebehaves the same). - Create a team folder
TF. Grant groupdept(membersalice,bob) all permissions. Enable advanced permissions. - Create the subfolders
TF/RestrictedandTF/Restricted/alice. occ groupfolders:permissions <id> --group dept Restricted -- -readocc groupfolders:permissions <id> --user alice Restricted/alice -- +read +write +create +deleteocc groupfolders:permissions <id> --test --user alice Restricted/alice→+read, +write, +create, +delete, +share- As
alice:PROPFIND /remote.php/dav/files/alice/TF/Restricted/alicewithDepth: 0(or1) → HTTP 500,<s:exception>TypeError</s:exception>. - As
alice:PUT /remote.php/dav/files/alice/TF/Restricted/alice/test.txt→ HTTP 500.
Variants tested, each in both acl-inherit-per-user modes:
Rule for dept on Restricted |
alice → Restricted/alice |
|---|---|
-read |
500 |
-read -write |
500 |
-read -write -create -delete -share |
500 |
+read -write -create -delete -share (parent readable), sibling folders denied |
207 (works) |
Users who can read Restricted (e.g. a group with +read on it) get 207 on Restricted/alice. Only users for whom an ancestor is unreadable hit the TypeError.
Expected behavior
No 500. Either the ACL-granted access (207), or, if readable ancestors are intentionally required, a 404 Not Found like the rest of getNodeForPath() produces.
Nextcloud Server version
34 (observed on 34.0.4)
Affected versions
- Observed: 34.0.4 (official image
nextcloud:34.0.4-apache). - By source inspection: the same unguarded
getFileInfo()→new Directory()lines exist since #54441 in 33.0.0 and later, stable33, stable34 (identical to 34.0.4), 35.0.0, 35.0.1 and master. stable32 does not have this code path. There is no 34.0.5 yet.
Operating system / PHP / Web server / Database
Official Docker image nextcloud:34.0.4-apache: Debian, PHP 8.5.10 (mod_php), Apache 2.4.68, behind a reverse proxy. PostgreSQL 18.6.
List of activated apps (relevant)
groupfolders 22.0.6, admin_audit 1.24.0, files_versions, files_trashbin, files_sharing (defaults of the image otherwise).
Additional info
Related: nextcloud/groupfolders#4984 (same TypeError, trashbin trigger). Introduced with nextcloud/server#54441 ("Add INodeByPath to Directory").
- Lenguaje dominante
- PHP
- Estrellas
- 37k
- Forks
- 5.3k
- Merge medio
- 2 d 1 h
- PR fusionados (30 d)
- 723
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de nextcloud/server
-
enhancement feature: TaskProcessing good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
1. to develop technical debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
0. Needs triage 35-feedback bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
0. Needs triage 35-feedback bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
Los mantenedores suelen responder en 1 día
-
0. Needs triage 35-feedback bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
Todos los issues de nextcloud/server
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 69/100
PrestaShop/PrestaShop#43140 ·
Los mantenedores suelen responder en 1 día
-
sync-en
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
sync-en
Dificultad 2/5 1-3 horas Aptitud para principiantes 83/100
Los mantenedores suelen responder en 3 días
-
[Bug] Report tables drop a metric's trailing zeros and cap it at two decimalsPosiblemente ocupada @lansow la tomó hoy. AbiertoPotential Bug triaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
matomo-org/matomo#25474 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
coollabsio/shoutrrr#190 ·