Repository navigation
Check for unprotected datadir stopped working in oC 10 #28344
Description
Activity
- ghost changed the title
[-]Check for unprotected datadir stopped working in oC 10?[/-][+]Check for unprotected datadir stopped working in oC 10[/+]on Jul 8, 2017 @kdslkdsaldsal not sure why the JS test would stop working, need to investigate
@kdslkdsaldsal works for me with 10.0.3beta:
- Setup OC on Apache
- Do not configure Apache as per the docs, which usually adds a block with
AllowOverideand others - Go to admin page
I see this:
Your data directory and your files are probably accessible from the Internet. The .htaccess file is not working. We strongly suggest that you configure your web server in a way that the data directory is no longer accessible or you move the data directory outside the web server document root.Maybe you discovered a slightly different setup where the ajax request to the test file doesn't go through despite the server being unprotected ?
If it still happens, can you check the network call to "htaccesstest.txt" ?
Maybe the sever failed to generate this file before opening the admin page ?@kdslkdsaldsal no worries. So this either tells us that the bug exists in 10.0.2 and is fixed in 10.0.3beta, or the bug still exists but there is a difference in the env.
Let's try it with the UCS appliance
Had a quick try locally with the release tarball 10.0.2 and I do see the warning appear.
I was told that both the demo instance and this appliance have their data folder in a separate folder. So maybe there's a bug in the data folder check that shows false positives when data folder is outside.
There is a orphaned data dir in Docker and Appliance. The configured data dir is another one. I guess the check only works on the configured one, not on the orphaned default one.
Hey, this issue has been closed because the label
needs infois set and there were no updates for 14 days. Feel free to reopen this issue if you deem it appropriate.
Not filling out the issue template as i could reproduce this reliable on demo.owncloud.org with a complete different setup then mine.
While doing #28343 i've noticed that ownCloud 10 seems to not warn about an unprotected data dir anymore:
The response to https://demo.owncloud.org/index.php/settings/ajax/checksetup is something like the below. Seems ownCloud thinks that the protection is working where it is indeed not working.
cc @PVince81 @Peter-Prochaska