mirror of https://github.com/nextcloud/server
Merge pull request #33500 from nextcloud/encryption-system-mount
add marker interface to mark system mount points for encryption
This commit is contained in:
commit
1b577d348b
|
@ -163,7 +163,7 @@ class ConfigAdapter implements IMountProvider {
|
|||
$storageConfig->getId()
|
||||
);
|
||||
} else {
|
||||
return new ExternalMountPoint(
|
||||
return new SystemMountPoint(
|
||||
$storageConfig,
|
||||
$storage,
|
||||
'/' . $user->getUID() . '/files' . $storageConfig->getMountPoint(),
|
||||
|
|
|
@ -0,0 +1,30 @@
|
|||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
/**
|
||||
* @copyright Copyright (c) 2022 Robin Appelman <robin@icewind.nl>
|
||||
*
|
||||
* @license GNU AGPL version 3 or any later version
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
* published by the Free Software Foundation, either version 3 of the
|
||||
* License, or (at your option) any later version.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU Affero General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU Affero General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*
|
||||
*/
|
||||
|
||||
namespace OCA\Files_External\Config;
|
||||
|
||||
|
||||
use OCP\Files\Mount\ISystemMountPoint;
|
||||
|
||||
class SystemMountPoint extends ExternalMountPoint implements ISystemMountPoint {
|
||||
}
|
|
@ -314,6 +314,7 @@ return array(
|
|||
'OCP\\Files\\Lock\\OwnerLockedException' => $baseDir . '/lib/public/Files/Lock/OwnerLockedException.php',
|
||||
'OCP\\Files\\Mount\\IMountManager' => $baseDir . '/lib/public/Files/Mount/IMountManager.php',
|
||||
'OCP\\Files\\Mount\\IMountPoint' => $baseDir . '/lib/public/Files/Mount/IMountPoint.php',
|
||||
'OCP\\Files\\Mount\\ISystemMountPoint' => $baseDir . '/lib/public/Files/Mount/ISystemMountPoint.php',
|
||||
'OCP\\Files\\Node' => $baseDir . '/lib/public/Files/Node.php',
|
||||
'OCP\\Files\\NotEnoughSpaceException' => $baseDir . '/lib/public/Files/NotEnoughSpaceException.php',
|
||||
'OCP\\Files\\NotFoundException' => $baseDir . '/lib/public/Files/NotFoundException.php',
|
||||
|
|
|
@ -347,6 +347,7 @@ class ComposerStaticInit749170dad3f5e7f9ca158f5a9f04f6a2
|
|||
'OCP\\Files\\Lock\\OwnerLockedException' => __DIR__ . '/../../..' . '/lib/public/Files/Lock/OwnerLockedException.php',
|
||||
'OCP\\Files\\Mount\\IMountManager' => __DIR__ . '/../../..' . '/lib/public/Files/Mount/IMountManager.php',
|
||||
'OCP\\Files\\Mount\\IMountPoint' => __DIR__ . '/../../..' . '/lib/public/Files/Mount/IMountPoint.php',
|
||||
'OCP\\Files\\Mount\\ISystemMountPoint' => __DIR__ . '/../../..' . '/lib/public/Files/Mount/ISystemMountPoint.php',
|
||||
'OCP\\Files\\Node' => __DIR__ . '/../../..' . '/lib/public/Files/Node.php',
|
||||
'OCP\\Files\\NotEnoughSpaceException' => __DIR__ . '/../../..' . '/lib/public/Files/NotEnoughSpaceException.php',
|
||||
'OCP\\Files\\NotFoundException' => __DIR__ . '/../../..' . '/lib/public/Files/NotFoundException.php',
|
||||
|
|
|
@ -32,10 +32,8 @@ use OC\Encryption\Exceptions\EncryptionHeaderToLargeException;
|
|||
use OC\Encryption\Exceptions\ModuleDoesNotExistsException;
|
||||
use OC\Files\Filesystem;
|
||||
use OC\Files\View;
|
||||
use OCA\Files_External\Lib\StorageConfig;
|
||||
use OCA\Files_External\Service\GlobalStoragesService;
|
||||
use OCP\App\IAppManager;
|
||||
use OCP\Encryption\IEncryptionModule;
|
||||
use OCP\Files\Mount\ISystemMountPoint;
|
||||
use OCP\IConfig;
|
||||
use OCP\IGroupManager;
|
||||
use OCP\IUser;
|
||||
|
@ -295,46 +293,9 @@ class Util {
|
|||
* @param string $uid
|
||||
* @return boolean
|
||||
*/
|
||||
public function isSystemWideMountPoint($path, $uid) {
|
||||
// No DI here as this initialise the db too soon
|
||||
if (\OCP\Server::get(IAppManager::class)->isEnabledForUser("files_external")) {
|
||||
/** @var GlobalStoragesService $storageService */
|
||||
$storageService = \OC::$server->get(GlobalStoragesService::class);
|
||||
$storages = $storageService->getAllStorages();
|
||||
foreach ($storages as $storage) {
|
||||
if (strpos($path, '/files/' . ltrim($storage->getMountPoint(), '/')) === 0) {
|
||||
if ($this->isMountPointApplicableToUser($storage, $uid)) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* check if mount point is applicable to user
|
||||
*
|
||||
* @param StorageConfig $mount
|
||||
* @param string $uid
|
||||
* @return boolean
|
||||
*/
|
||||
private function isMountPointApplicableToUser(StorageConfig $mount, string $uid) {
|
||||
if ($mount->getApplicableUsers() === [] && $mount->getApplicableGroups() === []) {
|
||||
// applicable for everyone
|
||||
return true;
|
||||
}
|
||||
// check if mount point is applicable for the user
|
||||
if (array_search($uid, $mount->getApplicableUsers()) !== false) {
|
||||
return true;
|
||||
}
|
||||
// check if mount point is applicable for group where the user is a member
|
||||
foreach ($mount->getApplicableGroups() as $gid) {
|
||||
if ($this->groupManager->isInGroup($uid, $gid)) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
public function isSystemWideMountPoint(string $path, string $uid) {
|
||||
$mount = Filesystem::getMountManager()->find('/' . $uid . $path);
|
||||
return $mount instanceof ISystemMountPoint;
|
||||
}
|
||||
|
||||
/**
|
||||
|
|
|
@ -0,0 +1,34 @@
|
|||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
/**
|
||||
* @copyright Copyright (c) 2022 Robin Appelman <robin@icewind.nl>
|
||||
*
|
||||
* @license GNU AGPL version 3 or any later version
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify
|
||||
* it under the terms of the GNU Affero General Public License as
|
||||
* published by the Free Software Foundation, either version 3 of the
|
||||
* License, or (at your option) any later version.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU Affero General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU Affero General Public License
|
||||
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*
|
||||
*/
|
||||
|
||||
namespace OCP\Files\Mount;
|
||||
|
||||
/**
|
||||
* Mark a mountpoint as containing system data, meaning that the data is not user specific
|
||||
*
|
||||
* Example use case is signaling to the encryption wrapper that system-wide keys should be used for a mountpoint
|
||||
*
|
||||
* @since 25.0.0
|
||||
*/
|
||||
interface ISystemMountPoint extends IMountPoint {
|
||||
}
|
Loading…
Reference in New Issue