]> dgit.raspbian.org Git - nextcloud-desktop.git/commitdiff
Folder: Make folder only accessible by user #5282 (#5315)
authorMarkus Goetz <markus@woboq.com>
Wed, 23 Nov 2016 10:05:41 +0000 (11:05 +0100)
committerGitHub <noreply@github.com>
Wed, 23 Nov 2016 10:05:41 +0000 (11:05 +0100)
Because on OS X the parent folder might not protect
against access.

src/gui/accountsettings.cpp
src/gui/owncloudsetupwizard.cpp
src/libsync/filesystem.cpp
src/libsync/filesystem.h

index c9dc992697de0730b67deac8152390eee88e7dd2..2e0f41eba1c4d4b19b4a75a2e8afdad3648c4956 100644 (file)
@@ -31,6 +31,7 @@
 #include "owncloudsetupwizard.h"
 #include "creds/abstractcredentials.h"
 #include "tooltipupdater.h"
+#include "filesystem.h"
 
 #include <math.h>
 
@@ -300,8 +301,9 @@ void AccountSettings::slotFolderWizardAccepted()
                                      tr("<p>Could not create local folder <i>%1</i>.")
                                         .arg(QDir::toNativeSeparators(definition.localPath)));
                 return;
+            } else {
+                FileSystem::setFolderMinimumPermissions(definition.localPath);
             }
-
         }
     }
 
index 993bf04f00742c7f933664ee451acf634d4ae246..b33e96bd9181b4d3f3f6e839f0e4d915e7528b1f 100644 (file)
@@ -31,6 +31,7 @@
 #include "sslerrordialog.h"
 #include "accountmanager.h"
 #include "clientproxy.h"
+#include "filesystem.h"
 
 #include "creds/credentialsfactory.h"
 #include "creds/abstractcredentials.h"
@@ -340,8 +341,8 @@ void OwncloudSetupWizard::slotCreateLocalAndRemoteFolders(const QString& localFo
     } else {
         QString res = tr("Creating local sync folder %1...").arg(localFolder);
         if( fi.mkpath( localFolder ) ) {
+            FileSystem::setFolderMinimumPermissions(localFolder);
             Utility::setupFavLink( localFolder );
-            // FIXME: Create a local sync folder.
             res += tr("ok");
         } else {
             res += tr("failed.");
index 70ed2cefdfcebda132325660edeaa2efcc0fbbeb..044ea39045b14f94f8d07033e76951d8d22ad251 100644 (file)
@@ -146,6 +146,17 @@ void FileSystem::setFileReadOnly(const QString& filename, bool readonly)
     file.setPermissions(permissions);
 }
 
+void FileSystem::setFolderMinimumPermissions(const QString& filename)
+{
+#ifdef Q_OS_MAC
+    QFile::Permissions perm = QFile::ReadOwner | QFile::WriteOwner | QFile::ExeOwner;
+    QFile file(filename);
+    file.setPermissions(perm);
+#else
+    Q_UNUSED(filename);
+#endif
+}
+
 
 void FileSystem::setFileReadOnlyWeak(const QString& filename, bool readonly)
 {
index 3daaefbb3356c3b77ac8b854757f2d41a1880d32..e53e873a960c0b32ac1702f07f0b576c7c914260 100644 (file)
@@ -67,6 +67,12 @@ void OWNCLOUDSYNC_EXPORT setFileReadOnly(const QString& filename, bool readonly)
  */
 void OWNCLOUDSYNC_EXPORT setFileReadOnlyWeak(const QString& filename, bool readonly);
 
+/**
+ * @brief Try to set permissions so that other users on the local machine can not
+ * go into the folder.
+ */
+void OWNCLOUDSYNC_EXPORT setFolderMinimumPermissions(const QString& filename);
+
 /** convert a "normal" windows path into a path that can be 32k chars long. */
 QString OWNCLOUDSYNC_EXPORT longWinPath( const QString& inpath );