Edouard Vanbelle
1e2882973b
fix(test): correct due to commit 43cf4a2bg
...
- MKCOL is now better protected
- Webdav now handle 201 (created) 204 (overritten)
2026-06-30 20:18:19 +02:00
Edouard Vanbelle
16ea08b093
feat(drive): improve Drive model
...
now Drive is purely a metadata
each drive has always a root folder
this model minimize Oxicloud changes, and simplify
the Drive name is simply the folder's root's name
note: owner of Drive has more permission that an owner of the root folder
2026-06-19 16:06:37 +02:00
Edouard Vanbelle
96097431c3
test(api): upgrade tests to new routes (don't use deprecated routes anymore)
2026-05-31 20:58:01 +02:00
Edouard Vanbelle
ac42a6d3cc
test(api): check right management for folder creation and folder move + check also webdsav MKCOL protection
...
│ Steps 1-6 │ Setup: admin's resources + create bob + bob's home folder │
│ Step 7 │ REST: bob can't create a folder inside admin's home → 404 │
│ Step 8 │ REST: bob can't create inside admin's private folder → 404 │
│ Step 9 │ REST: parent_id: null auto-resolves to bob's home (documents the convenience) │
│ Step 10 │ REST: positive control — bob creates in his own home → 201 │
│ Step 12 │ REST: bob can't move his file into admin's folder → 404 │
│ Step 13 │ REST: bob moves file to root (null) → 200 (legitimate root state) │
│ Step 14 │ REST: bob can't read admin's file → 404 │
│ Step 15 │ REST: admin's tree integrity preserved │
│ Step 16 │ WebDAV: path-prefix isolation rewrites cross-user paths into caller's tree │
│ Step 17 │ WebDAV: positive control MKCOL in bob's own tree → 201 │
│ Step 18 │ WebDAV: bob's home contains the rewritten "My Folder - admin" sub-folder, proving the isolation rerouted the attack │
│ Step 19 │ WebDAV: admin's tree never sees bob's WebDAV traffic │
2026-05-20 13:04:15 +02:00