fix(webdav): reject PROPPATCH on protected DAV:/oc:/nc:/ocs: props

DeadPropertyStore let PROPPATCH set any namespace/name verbatim,
incl. names the server itself emits as live state (DAV: entirely,
plus oc:/nc:/ocs: names used by write_file_response /
write_folder_response). That either forges a live prop or stores
dead rows nothing ever reads. is_protected_property() denylists
them; both PROPPATCH handlers (native + NC) now return per-property
403 instead of storing. oc:favorite stays writable via its existing
special-case, which runs before the protection check.
This commit is contained in:
M.Schmidt
2026-07-01 22:54:48 +02:00
parent 94e0145855
commit 0ad0ea1a43
3 changed files with 54 additions and 2 deletions
@@ -72,6 +72,46 @@ impl std::fmt::Display for QualifiedName {
}
}
/// Whether PROPPATCH must refuse to set/remove this property as a dead
/// property (RFC 4918 §9.2 — server MAY reject a PROPPATCH attempt on a
/// live property; DeadPropertyStore has no business holding a value that
/// PROPFIND / REPORT already emit from live server state).
pub fn is_protected_property(qn: &QualifiedName) -> bool {
match qn.namespace.as_str() {
// RFC 4918 §15 — the DAV: namespace is server-owned in its
// entirety. Any PROPPATCH into it either forges a live
// property (dual-emission) or accumulates unread garbage
// (silent litter).
"DAV:" => true,
// Every name below appears verbatim in write_folder_response
// / write_file_response in the NC handler. Adding a new
// live emitter → add its name here.
"http://owncloud.org/ns" => matches!(
qn.name.as_str(),
"favorite"
| "fileid"
| "id"
| "owner-id"
| "owner-display-name"
| "permissions"
| "share-types"
| "size"
),
"http://nextcloud.org/ns" => matches!(
qn.name.as_str(),
"has-preview" | "is-encrypted" | "mount-type" | "creation_time" | "upload_time"
),
"http://open-collaboration-services.org/ns" => {
matches!(qn.name.as_str(), "share-permissions")
}
_ => false,
}
}
/// PROPFIND request type
#[derive(Debug, PartialEq)]
pub enum PropFindType {