Repository navigation
Consider unreadable remote folders (e.g. negative ACLs) #4622
Description
Activity
- changed the title
[-]Consider unreadable folders for the sync protocol[/-][+]Consider unreadable remote folders[/+]on Mar 30, 2016 This discussion should include @DeepDiver1975
Here is a related problem to solve: suppose that I change the ACL to give access to a directory which was not readible before. I would assume that a change in ACL should result in an ETAG change and client would PROPFIND again the parent and read the new ACL and access the directory.
What happens today? What is the current user experience?
The current user experience is bad: in this case the client shows 403 error and aborts current sync run. The it restarts a new run which shows 403 and aborts. And so on.
BTW, we already have handling for temporarily unavailable storages in the client:
https://github.com/owncloud/client/blob/master/csync/src/csync_update.c#L695
- Given a folder is unreadable in a mounted external storage, the sync client must not stop syncing.
- In the filecache mark the folder as unreadable, so a PROPFIND or other access will not provide contents. Ideally including information about the permissions.
@butonic
@butonic @tomneedham How can the server-side be improved to handle such situations?
- addedp1-urgentConsider a hotfix release with only that fix (ex: lose trust, money, security issue, ...)Consider a hotfix release with only that fix (ex: lose trust, money, security issue, ...)and removed
on Jul 12, 2017 As @guruz mentioned, there's already code to handle 403s returning from the server. Probably what we need is to be certain that the server identifies the "unauthorized"/"unavailable" situations and return the right HTTP code. (See owncloud/core#28598 as example)
@SamuAlfageme adding a comment to #4622 (comment) Sometimes the oc_filecache has still old files/share that doesn't exist anymore.
Anocc files:scanto that path solves most of the time the problem, but the client loops until the admin update theoc_filescachetable.A temporarily unavailable in main storage should not be possible. (The server should take care to update the cache table.) - I have often seen in many issues!
In external storages should probably have a different approach.
@SamuAlfageme will reproduce and describe a solution, maybe best in a new ticket.
- added and removedp1-urgentConsider a hotfix release with only that fix (ex: lose trust, money, security issue, ...)Consider a hotfix release with only that fix (ex: lose trust, money, security issue, ...)
on Apr 9, 2018 Bumping this one as it's relevant to the whole "negative-acl" feature we recently introduced on CERNBox.
- changed the title
[-]Consider unreadable remote folders[/-][+]Consider unreadable remote folders (e.g. negative ACLs)[/+]on Nov 1, 2022
This is partially related to #4621.
When accessing externally mounted storage (or in our case parts of the underlying filesystem) certain folders may not be readable by the current user (because of underlying ACLs preventing the user to read the folder). This case should be properly recognized by the sync client.
The implementation should consider two cases: