sharing/bday: do not permit permissions eE
This commit is contained in:
@@ -880,9 +880,9 @@ class BaseSharing:
|
|||||||
else:
|
else:
|
||||||
Permissions = str(Permissions)
|
Permissions = str(Permissions)
|
||||||
if Conversion == "bday":
|
if Conversion == "bday":
|
||||||
# bday is read-only
|
# bday is read-only and not supporting "Ee"
|
||||||
for permission in Permissions:
|
for permission in Permissions:
|
||||||
if permission not in "rPpEe":
|
if permission not in "rPp":
|
||||||
logger.warning(api_info + ": PathMapped=%r Permissions=%r not supported for Conversion=%r", PathMapped, Permissions, Conversion)
|
logger.warning(api_info + ": PathMapped=%r Permissions=%r not supported for Conversion=%r", PathMapped, Permissions, Conversion)
|
||||||
return httputils.METHOD_NOT_ALLOWED
|
return httputils.METHOD_NOT_ALLOWED
|
||||||
|
|
||||||
@@ -1081,6 +1081,15 @@ class BaseSharing:
|
|||||||
logger.trace("" + api_info + ": clear property %r", prop)
|
logger.trace("" + api_info + ": clear property %r", prop)
|
||||||
del Properties[prop]
|
del Properties[prop]
|
||||||
|
|
||||||
|
if Permissions is not None and share['Conversion'] is not None:
|
||||||
|
Permissions = str(Permissions)
|
||||||
|
if share['Conversion'] == "bday":
|
||||||
|
# bday is read-only and not supporting "Ee"
|
||||||
|
for permission in Permissions:
|
||||||
|
if permission not in "rPp":
|
||||||
|
logger.warning(api_info + ": PathMapped=%r Permissions=%r not supported for Conversion=%r", PathMapped, Permissions, Conversion)
|
||||||
|
return httputils.METHOD_NOT_ALLOWED
|
||||||
|
|
||||||
if user == share['Owner']:
|
if user == share['Owner']:
|
||||||
if PathMapped is not None:
|
if PathMapped is not None:
|
||||||
# check access Permissions
|
# check access Permissions
|
||||||
|
|||||||
Reference in New Issue
Block a user