sharing: URL-encode-aware backmap of REPORT/PROPPATCH hrefs

make_href percent-encodes hrefs (an '@' in an email principal becomes
%40), but the backmap compared against the raw PathMapped, so the
rewrite was skipped and the owner's real path leaked -- editing a shared
collection then failed with 403. Compare and rewrite on the quoted form.
This commit is contained in:
Arkadiusz Juszczyk
2026-06-24 01:02:28 +02:00
parent 5c69056c46
commit 828691e3c4
3 changed files with 10 additions and 6 deletions

View File

@@ -25,6 +25,7 @@ import socket
import xml.etree.ElementTree as ET
from http import client
from typing import Dict, Optional, Union, cast
from urllib.parse import quote
import defusedxml.ElementTree as DefusedET
@@ -49,8 +50,8 @@ def xml_proppatch(base_prefix: str, path: str,
href = ET.Element(xmlutils.make_clark("D:href"))
href.text = xmlutils.make_href(base_prefix, path)
if share:
# backmap
href.text = href.text.replace(share['PathMapped'], share['PathOrToken'])
# backmap; quote so the encoded href and raw share path compare
href.text = href.text.replace(quote(share['PathMapped']), quote(str(share['PathOrToken'])))
response.append(href)
# Create D:propstat element for props with status 200 OK
propstat = ET.Element(xmlutils.make_clark("D:propstat"))