Edouard Vanbelle
|
12466d4b83
|
feat(roles): simplify roles to only Viewer, Editor, Admin
┌────────┬──────┬─────────┬────────┬────────┬───────┬────────┐
│ Role │ read │ comment │ create │ update │ share │ delete │
├────────┼──────┼─────────┼────────┼────────┼───────┼────────┤
│ viewer │ ✓ │ │ │ │ │ │
├────────┼──────┼─────────┼────────┼────────┼───────┼────────┤
│ editor │ ✓ │ ✓ │ ✓ │ ✓ │ │ │
├────────┼──────┼─────────┼────────┼────────┼───────┼────────┤
│ admin │ ✓ │ ✓ │ ✓ │ ✓ │ ✓ │ ✓ │
└────────┴──────┴─────────┴────────┴────────┴───────┴────────┘
|
2026-05-25 22:47:36 +02:00 |
|
Edouard Vanbelle
|
dd68d783e0
|
fix(authz): permit policiy: a user with Delete permission can delete a file/folder. Only the owner can permanently delete or restore a trashed item
|
2026-05-21 22:45:49 +02:00 |
|
Edouard Vanbelle
|
a1c21ce446
|
refactor(authz): permet require_permission() as has_permission(), more explicit
|
2026-05-21 21:50:42 +02:00 |
|
Edouard Vanbelle
|
cb35775f77
|
fix(dedub): correct ref count on hashes, many thanks to you api tests...
|
2026-05-21 21:12:38 +02:00 |
|
Edouard Vanbelle
|
eb95567a7d
|
feat(authz): test & cover batch cases
┌────────────────────────────────┬─────────────────────────────────┬───────────────────────┬─────────────────┬──────────────────────────────┐
│ Endpoint │ Phase 3A no-grant │ Phase 3B Viewer │ Phase 3C Editor │ Phase 3D Admin │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/get │ 400 (all failed) │ 200 (2 successful) │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/move │ 400 │ 400 (no Update) │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/copy │ 400 │ — │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/files/delete │ 400 │ 400 │ 400 (no Delete) │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/get │ 400 │ 200 │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/create │ 400 │ — │ 201 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/move │ 400 │ — │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/copy │ 400 │ — │ 200 │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/folders/delete │ 400 │ — │ 400 (no Delete) │ 200 │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/trash │ 400 │ — │ — │ 400 (owner-only, documented) │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ POST /api/batch/download │ 404 (NotFound) │ 200 + application/zip │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ GET /api/batch/download?... │ 404 │ 200 + zip │ — │ — │
├────────────────────────────────┼─────────────────────────────────┼───────────────────────┼─────────────────┼──────────────────────────────┤
│ Phase 3E lifecycle cleanup │ grants table empty after delete │ │ │ │
└────────────────────────────────┴─────────────────────────────────┴───────────────────────┴─────────────────┴──────────────────────────────┘
|
2026-05-21 20:30:58 +02:00 |
|
Edouard Vanbelle
|
a53c09f361
|
feat(authz): covert and test chunked upload with permissions
|
2026-05-21 20:30:58 +02:00 |
|
Edouard Vanbelle
|
bd1b17b589
|
test(grants): full coverate of /api/files and /api/folders
|
2026-05-21 20:30:58 +02:00 |
|
Edouard Vanbelle
|
cba9be8c21
|
feat(rebac): first pass
|
2026-05-20 22:56:00 +02:00 |
|
Edouard Vanbelle
|
ac42a6d3cc
|
test(api): check right management for folder creation and folder move + check also webdsav MKCOL protection
│ Steps 1-6 │ Setup: admin's resources + create bob + bob's home folder │
│ Step 7 │ REST: bob can't create a folder inside admin's home → 404 │
│ Step 8 │ REST: bob can't create inside admin's private folder → 404 │
│ Step 9 │ REST: parent_id: null auto-resolves to bob's home (documents the convenience) │
│ Step 10 │ REST: positive control — bob creates in his own home → 201 │
│ Step 12 │ REST: bob can't move his file into admin's folder → 404 │
│ Step 13 │ REST: bob moves file to root (null) → 200 (legitimate root state) │
│ Step 14 │ REST: bob can't read admin's file → 404 │
│ Step 15 │ REST: admin's tree integrity preserved │
│ Step 16 │ WebDAV: path-prefix isolation rewrites cross-user paths into caller's tree │
│ Step 17 │ WebDAV: positive control MKCOL in bob's own tree → 201 │
│ Step 18 │ WebDAV: bob's home contains the rewritten "My Folder - admin" sub-folder, proving the isolation rerouted the attack │
│ Step 19 │ WebDAV: admin's tree never sees bob's WebDAV traffic │
|
2026-05-20 13:04:15 +02:00 |
|
Edouard Vanbelle
|
78cb37b311
|
feat: check thumbnail cleanup on files deletion + correct ref counter
|
2026-05-13 15:55:38 +02:00 |
|
Edouard Vanbelle
|
07d1f18bf4
|
test API thumbnail fix on updates
|
2026-05-13 10:17:47 +02:00 |
|
Edouard Vanbelle
|
e953236589
|
test(api): add functional test on copy_folder
|
2026-05-12 00:28:42 +02:00 |
|
Edouard Vanbelle
|
a0aa9c5cd1
|
ci: trigger test on /tests change
|
2026-05-11 20:00:22 +02:00 |
|
Edouard Vanbelle
|
5df4075f7f
|
test(api): add API test coverage on files, folders, favorites, recent, trash
|
2026-05-11 19:31:12 +02:00 |
|
Edouard Vanbelle
|
d8625b9f39
|
ci: merge end-to-end workflow into ci, permits to reduce amount of built
|
2026-05-11 12:10:15 +02:00 |
|
Edouard Vanbelle
|
cc14ec53ee
|
ci(api-tests): add API test to CI
|
2026-05-11 10:53:59 +02:00 |
|
Edouard Vanbelle
|
8ab537797a
|
test(api): add API test on contacts
next will be to add CI on it
|
2026-05-11 00:53:29 +02:00 |
|