-
Notifications
You must be signed in to change notification settings - Fork 186
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Graph delete request leaks existence of space #5031
Labels
Priority:p4-low
Low priority
Severity:sev4-low
no loss of service, req. for docs info or enhancement
Topic:good-first-issue
Topic:Security
Type:Bug
Comments
C0rby
added
Type:Bug
Topic:Security
Priority:p4-low
Low priority
Severity:sev4-low
no loss of service, req. for docs info or enhancement
labels
Nov 10, 2022
2403905
added a commit
to 2403905/ocis
that referenced
this issue
May 3, 2023
9 tasks
2403905
added a commit
to 2403905/ocis
that referenced
this issue
May 3, 2023
2403905
added a commit
to 2403905/ocis
that referenced
this issue
May 5, 2023
2403905
added a commit
to 2403905/ocis
that referenced
this issue
May 5, 2023
2403905
added a commit
to 2403905/ocis
that referenced
this issue
May 8, 2023
micbar
added a commit
that referenced
this issue
May 8, 2023
fix Graph delete request leaks existence of space #5031
github-project-automation
bot
moved this from In progress
to Done
in Infinite Scale Team Board
May 8, 2023
ownclouders
pushed a commit
that referenced
this issue
May 8, 2023
fix Graph delete request leaks existence of space #5031
fschade
pushed a commit
that referenced
this issue
Jul 10, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Priority:p4-low
Low priority
Severity:sev4-low
no loss of service, req. for docs info or enhancement
Topic:good-first-issue
Topic:Security
Type:Bug
Context
oCIS version: v2.0.0-rc.1
Issue
A user could guess space ids of spaces they don't have access to.
Since we are using uuidv4 it's improbable so this issue has a low priority.
Admin space id:
Non existing space id:
Expected
The user should receive a generic error like "drive not found" or something like that if they can't access the drive.
The text was updated successfully, but these errors were encountered: