fix(security): patch critical IDOR & auth vulnerabilities
- Fix logout no-op: extract refresh token from cookie/body (auth_handler) - Secure all 12 WebDAV handlers with AuthUser + resolve_path_for_user - Secure all 7 batch handlers with caller_id ownership checks - Add _owned variants: copy_file_owned, delete_file_owned, get_file_stream_owned, get_folder_owned - Secure list_files_query: add AuthUser, SQL-level user_id filter, tenant-isolated ETag - Remove deprecated unscoped resolve_path() and exists() from PathResolverService - Remove dead list_files handler (unmounted, no auth) - Add list_files_for_owner (SQL) and list_files_owned across trait chain
This commit is contained in:
@@ -355,6 +355,10 @@ impl FolderUseCase for StubFolderUseCase {
|
||||
Ok(FolderDto::default())
|
||||
}
|
||||
|
||||
async fn get_folder_owned(&self, _id: &str, _caller_id: &str) -> Result<FolderDto, DomainError> {
|
||||
Ok(FolderDto::default())
|
||||
}
|
||||
|
||||
async fn get_folder_by_path(&self, _path: &str) -> Result<FolderDto, DomainError> {
|
||||
Ok(FolderDto::default())
|
||||
}
|
||||
@@ -490,6 +494,14 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
|
||||
Ok(Vec::new())
|
||||
}
|
||||
|
||||
async fn list_files_owned(
|
||||
&self,
|
||||
_folder_id: Option<&str>,
|
||||
_owner_id: &str,
|
||||
) -> Result<Vec<FileDto>, DomainError> {
|
||||
Ok(Vec::new())
|
||||
}
|
||||
|
||||
async fn get_file_stream(
|
||||
&self,
|
||||
_id: &str,
|
||||
@@ -498,6 +510,15 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
|
||||
Ok(Box::new(empty_stream))
|
||||
}
|
||||
|
||||
async fn get_file_stream_owned(
|
||||
&self,
|
||||
_id: &str,
|
||||
_caller_id: &str,
|
||||
) -> Result<Box<dyn Stream<Item = Result<Bytes, std::io::Error>> + Send>, DomainError> {
|
||||
let empty_stream = futures::stream::empty::<Result<Bytes, std::io::Error>>();
|
||||
Ok(Box::new(empty_stream))
|
||||
}
|
||||
|
||||
async fn get_file_optimized(
|
||||
&self,
|
||||
_id: &str,
|
||||
@@ -591,6 +612,15 @@ impl FileManagementUseCase for StubFileManagementUseCase {
|
||||
Ok(FileDto::default())
|
||||
}
|
||||
|
||||
async fn copy_file_owned(
|
||||
&self,
|
||||
_file_id: &str,
|
||||
_caller_id: &str,
|
||||
_folder_id: Option<String>,
|
||||
) -> Result<FileDto, DomainError> {
|
||||
Ok(FileDto::default())
|
||||
}
|
||||
|
||||
async fn rename_file(&self, _file_id: &str, _new_name: &str) -> Result<FileDto, DomainError> {
|
||||
Ok(FileDto::default())
|
||||
}
|
||||
@@ -599,6 +629,10 @@ impl FileManagementUseCase for StubFileManagementUseCase {
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn delete_file_owned(&self, _id: &str, _caller_id: &str) -> Result<(), DomainError> {
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn delete_with_cleanup(&self, _id: &str, _user_id: &str) -> Result<bool, DomainError> {
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user