fix(security): patch 3 vulnerabilities — IDOR, ownership bypass, XSS
V1: Add owner-scoped folder pagination (list_folders_by_owner_paginated) - New method in FolderRepository trait, PG implementation, service & handler - Prevents IDOR by filtering folder listings to authenticated user V2: Enforce ownership checks on folder mutations - rename_folder, move_folder, delete_folder now require caller_id - Service verifies folder.owner_id == caller_id (returns 404 on mismatch) - Propagated to folder_handler, batch_handler, batch_operations, webdav_handler - delete_folder_with_trash upgraded from OptionalAuthUser to AuthUser - download_folder_zip now checks ownership before streaming V3: Fix XSS in frontend via DOM APIs - sharedView.js: innerHTML → createElement + textContent - contextMenus.js: innerHTML → DOM construction for share dialog Cleanup: removed unused OptionalAuthUser import, updated all stubs/mocks
This commit is contained in:
@@ -313,7 +313,7 @@
|
||||
"fa": "Persiano",
|
||||
"fr": "Francese",
|
||||
"de": "Tedesco",
|
||||
"pt": "Portoghese"
|
||||
"pt": "Portoghese",
|
||||
"it": "Italiano"
|
||||
}
|
||||
},
|
||||
@@ -340,5 +340,13 @@
|
||||
"folder_deleted": "Cartella spostata nel cestino",
|
||||
"item_deleted_permanently": "Elemento eliminato definitivamente",
|
||||
"trash_emptied": "Cestino svuotato con successo"
|
||||
},
|
||||
"batch": {
|
||||
"one_selected": "1 elemento selezionato",
|
||||
"n_selected": "{{count}} elementi selezionati",
|
||||
"confirm_delete": "Sei sicuro di voler spostare {{count}} elementi nel cestino?",
|
||||
"move_title": "Sposta {{count}} elemento/i",
|
||||
"add_favorites": "Aggiungi ai preferiti",
|
||||
"move_copy": "Sposta o copia"
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user