Shared addressbook is always writable independently on "can edit" checkbox #23273

Closed
p5n opened this Issue Mar 15, 2016 · 6 comments

Projects

None yet

4 participants

@p5n
p5n commented Mar 15, 2016

Steps to reproduce

  1. Share addressbook with group (I used LDAP authentication)
  2. Remove "can edit" check
  3. Login with user that should have read-only access and drop contacts from addressbook

Expected behaviour

AB obviously should be read only

Actual behaviour

Any user can drop contents of shared addressbook

Database: mariadb

PHP version: 7.0.4

ownCloud version: (see ownCloud admin page) 9.0.0

Updated from an older ownCloud or fresh install: updated many times from some ancient version

Also I tried to change access to 2 or 3 in oc_dav_shares, but AB editable anyway

@p5n
p5n commented Mar 17, 2016

Sorry, probably whole contact cannot be dropped, but anyway contacts are editable.

@DeepDiver1975 DeepDiver1975 self-assigned this Mar 17, 2016
@DeepDiver1975
Member

Share addressbook with group

does this apply to user based shares as well? THX

@p5n
p5n commented Mar 17, 2016

Yes, I was able to remove Notes field and edit Groups in AB shared directly to me by username.

@DeepDiver1975
Member

What client are you using?

@p5n
p5n commented Mar 17, 2016

Web UI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment