Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 16 additions & 4 deletions lib/acl-checker.js
Original file line number Diff line number Diff line change
Expand Up @@ -87,15 +87,27 @@ class ACLChecker {
}
let accessDenied = aclCheck.accessDenied(acl.graph, resource, directory, aclFile, agent, modes, agentOrigin, trustedOrigins, originTrustedModes)

function accessDeniedForAccessTo (mode) {
const accessDeniedAccessTo = aclCheck.accessDenied(acl.graph, directory, null, aclFile, agent, [ACL(mode)], agentOrigin, trustedOrigins, originTrustedModes)
const accessResult = !accessDenied && !accessDeniedAccessTo
accessDenied = accessResult ? false : accessDenied || accessDeniedAccessTo
// debugCache('accessDenied result ' + accessDenied)
}
// For create and update HTTP methods
if ((method === 'PUT' || method === 'PATCH' || method === 'COPY') && directory) {
// if resource and acl have same parent container,
// and resource does not exist, then accessTo Append from parent is required
if (directory.value === dirname(aclFile.value) + '/' && !resourceExists) {
const accessDeniedAccessTo = aclCheck.accessDenied(acl.graph, directory, null, aclFile, agent, [ACL('Append')], agentOrigin, trustedOrigins, originTrustedModes)
const accessResult = !accessDenied && !accessDeniedAccessTo
accessDenied = accessResult ? false : accessDenied || accessDeniedAccessTo
// debugCache('accessDenied result ' + accessDenied)
accessDeniedForAccessTo('Append')
}
}

// For delete HTTP method
if ((method === 'DELETE') && directory) {
// if resource and acl have same parent container,
// then accessTo Write from parent is required
if (directory.value === dirname(aclFile.value) + '/') {
accessDeniedForAccessTo('Write')
}
}
if (accessDenied && user) {
Expand Down
2 changes: 1 addition & 1 deletion test/surface/run-solid-test-suite.sh
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ waitForNss server
runTests webid-provider-tests v2.0.3
runTests solid-crud-tests nss-skips
waitForNss thirdparty
runTests web-access-control-tests v5.1.0
runTests web-access-control-tests v6.0.0
teardown

# To debug, e.g. running web-access-control-tests jest interactively,
Expand Down