[Bug]: WebDAV TypeError (HTTP 500) in Directory::getNodeForPath when an ancestor is hidden by a Team folders ACL (Directory.php:571)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
从 apps/dav/lib/Connector/Sabre/Directory.php 中 getNodeForPath() 第571行附近开始,追踪祖先的 getFileInfo() 结果是如何处理的;报告称它可能在 Directory 构造函数之前返回 false。检查此路径的相关测试,并添加对不可读取祖先的覆盖。完成标准是请求不再产生 TypeError/HTTP 500,且行为符合预期的“未找到”或“已授予访问权限”响应。
由索引模型根据 Issue 内容生成。
描述
Bug description
A WebDAV request for a folder whose parent is not readable to the user returns HTTP 500 (TypeError) instead of a clean response, when the parent is hidden by a Team folders (groupfolders) ACL rule.
OCA\DAV\Connector\Sabre\Directory::getNodeForPath() walks up the ancestors to check that each one is readable (added in #54441, "to keep ACL checks working in files_accesscontrol"):
// apps/dav/lib/Connector/Sabre/Directory.php, v34.0.4, lines 569-571
$info = $this->fileView->getFileInfo($scanPath, false);
$directory = new Directory($this->fileView, $info, $this->tree, $this->shareManager);
$readable = $directory->getNode()->isReadable();
For an ancestor that a groupfolders ACL makes unreadable, View::getFileInfo() returns false, not an unreadable FileInfo. The false reaches the Directory constructor unchecked, which throws:
TypeError: OCA\DAV\Connector\Sabre\Directory::__construct(): Argument #2 ($info) must be of type OCP\Files\FileInfo,
false given, called in /var/www/html/apps/dav/lib/Connector/Sabre/Directory.php on line 571
#00 OCA\DAV\Connector\Sabre\Directory->__construct() apps/dav/lib/Connector/Sabre/Directory.php:571
#01 OCA\DAV\Connector\Sabre\Directory->getNodeForPath() 3rdparty/sabre/dav/lib/DAV/Tree.php:86
#02 Sabre\DAV\Tree->getNodeForPath() 3rdparty/sabre/dav/lib/DAV/Server.php:971
#03 Sabre\DAV\Server->getPropertiesIteratorForPath() 3rdparty/sabre/dav/lib/DAV/Server.php:1664
#04 Sabre\DAV\Server->writeMultiStatus() 3rdparty/sabre/dav/lib/DAV/Server.php:1649
#05 Sabre\DAV\Server->generateMultiStatus() 3rdparty/sabre/dav/lib/DAV/CorePlugin.php:346
#06 Sabre\DAV\CorePlugin->httpPropFind() 3rdparty/sabre/event/lib/WildcardEmitterTrait.php:89
#07 Sabre\DAV\Server->emit() 3rdparty/sabre/dav/lib/DAV/Server.php:472
#08 Sabre\DAV\Server->invokeMethod() apps/dav/lib/Connector/Sabre/Server.php:215
#09 OCA\DAV\Connector\Sabre\Server->start() apps/dav/lib/Server.php:434
#10 OCA\DAV\Server->exec() apps/dav/appinfo/v2/remote.php:25
#11 require_once() remote.php:152
Uploads fail the same way. A PUT into the folder reaches the same line through OCA\DAV\Upload\ChunkingV2Plugin->beforePut() → prepareUpload() (ChunkingV2Plugin.php:171 / 342) → Tree->getNodeForPath().
This also blocks the legitimate case
This isn't only a configuration that is "unsupported by design":
- The ACL engine grants the access.
occ groupfolders:permissions <id> --test --user alice Restricted/alicereports+read, +write, +create, +delete, +share, and the web UI / ACL model let admins configure exactly this. Users with a valid grant get a server error instead of either their data or a clean denial. Desktop clients see a 500, not a 403/404, so they can't tell "no access" from "server broken". - The same unguarded call has another trigger with no ACL involved. Groupfolders trashbin entries over WebDAV hit it too: nextcloud/groupfolders#4984 (same TypeError, same
getNodeForPathchain, NC 33.0.7 / groupfolders 21.0.13, open). Any path wheregetFileInfo()returnsfalsefor an ancestor turns into a 500.
Whatever the intended outcome is (207 because the ACL grants read, or 404 because the parent is unreadable, as the loop's NotFound suggests), a TypeError/500 shouldn't be the answer. A minimal fix would treat $info === false like an unreadable ancestor and throw NotFound.
Steps to reproduce
- Nextcloud 34.0.4 with Team folders 22.0.6 (
groupfolders/acl-inherit-per-userat its defaultfalse;truebehaves the same). - Create a team folder
TF. Grant groupdept(membersalice,bob) all permissions. Enable advanced permissions. - Create the subfolders
TF/RestrictedandTF/Restricted/alice. occ groupfolders:permissions <id> --group dept Restricted -- -readocc groupfolders:permissions <id> --user alice Restricted/alice -- +read +write +create +deleteocc groupfolders:permissions <id> --test --user alice Restricted/alice→+read, +write, +create, +delete, +share- As
alice:PROPFIND /remote.php/dav/files/alice/TF/Restricted/alicewithDepth: 0(or1) → HTTP 500,<s:exception>TypeError</s:exception>. - As
alice:PUT /remote.php/dav/files/alice/TF/Restricted/alice/test.txt→ HTTP 500.
Variants tested, each in both acl-inherit-per-user modes:
Rule for dept on Restricted |
alice → Restricted/alice |
|---|---|
-read |
500 |
-read -write |
500 |
-read -write -create -delete -share |
500 |
+read -write -create -delete -share (parent readable), sibling folders denied |
207 (works) |
Users who can read Restricted (e.g. a group with +read on it) get 207 on Restricted/alice. Only users for whom an ancestor is unreadable hit the TypeError.
Expected behavior
No 500. Either the ACL-granted access (207), or, if readable ancestors are intentionally required, a 404 Not Found like the rest of getNodeForPath() produces.
Nextcloud Server version
34 (observed on 34.0.4)
Affected versions
- Observed: 34.0.4 (official image
nextcloud:34.0.4-apache). - By source inspection: the same unguarded
getFileInfo()→new Directory()lines exist since #54441 in 33.0.0 and later, stable33, stable34 (identical to 34.0.4), 35.0.0, 35.0.1 and master. stable32 does not have this code path. There is no 34.0.5 yet.
Operating system / PHP / Web server / Database
Official Docker image nextcloud:34.0.4-apache: Debian, PHP 8.5.10 (mod_php), Apache 2.4.68, behind a reverse proxy. PostgreSQL 18.6.
List of activated apps (relevant)
groupfolders 22.0.6, admin_audit 1.24.0, files_versions, files_trashbin, files_sharing (defaults of the image otherwise).
Additional info
Related: nextcloud/groupfolders#4984 (same TypeError, trashbin trigger). Introduced with nextcloud/server#54441 ("Add INodeByPath to Directory").
- 主要语言
- PHP
- 星标
- 37k
- 派生
- 5.3k
- 平均合并
- 2 天 1 小时
- 30 天内合并 PR
- 723
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
nextcloud/server 的其他 Issue
-
enhancement feature: TaskProcessing good first issue
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
1. to develop technical debt
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
0. Needs triage 35-feedback bug
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
0. Needs triage 35-feedback bug
难度 1/5 1 小时以内 新手友好度 92/100
维护者通常 1 天内回复
-
0. Needs triage 35-feedback bug
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
相似的 Issue
-
Bug Enhancement Performance
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
Feature Status: Needs Triage
难度 2/5 1-3 小时 新手友好度 73/100
维护者通常 1 天内回复
-
frontend low-priority
难度 2/5 1-3 小时 新手友好度 77/100
mplodowski/dynamicpdf-plugin#336 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
AdvancedCustomFields/acf#1044 ·
-
Add Zammad可能已有人在做 @Arslan-TR 今天认领。 未关闭request
难度 2/5 1-3 小时 新手友好度 66/100
endoflife-date/endoflife.date#11298 · 1 条评论 ·
维护者通常 1 天内回复