fix(security): scope root folder listing to authenticated user

Non-admin users were seeing all users' root folders, including the
admin's. Three root causes fixed:

1. Backend: list_root_folders now extracts AuthUser and filters
   results so each user only sees their own home folder at the
   root level (folders matching 'My Folder - {username}' or
   'Mi Carpeta - {username}').

2. Frontend: findUserHomeFolder() searched only for the Spanish
   pattern 'Mi Carpeta - {username}' but the backend creates
   folders with the English pattern 'My Folder - {username}'.
   Now checks both naming conventions.

3. Frontend: when the home folder was not found, the code fell
   back to folderList[0] — which was usually the admin's folder.
   Removed that dangerous fallback; now shows empty root instead.

Fixes #94
This commit is contained in:
Dionisio
2026-02-13 22:31:05 +01:00
parent ce9971b9e4
commit 05135529ce
3 changed files with 85 additions and 39 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
// OxiCloud Service Worker
const CACHE_NAME = 'oxicloud-cache-v4';
const CACHE_NAME = 'oxicloud-cache-v5';
const ASSETS_TO_CACHE = [
'/',
'/index.html',