Skip to content

[stable33] fix(files_sharing): reject custom share tokens longer than the db column - #61675

Draft
backportbot[bot] wants to merge 2 commits into
stable33from
backport/61630/stable33
Draft

backportbot[bot] wants to merge 2 commits into
stable33from
backport/61630/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Jun 30, 2026 •

Copy link
Copy Markdown

Backport of #61630

Warning, This backport's changes differ from the original and might be incomplete ⚠️

Todo

  • Review and resolve any conflicts
  • Review and verify the backported changes
  • Amend HEAD commit to remove the line stating to skip CI

Learn more about backports at https://docs.nextcloud.com/server/stable/go.php?to=developer-backports.

amitmishra11 and others added 2 commits June 30, 2026 13:58
…se column

validateToken() only checked for an empty string and an invalid
character set, not length. A custom share token longer than 32
characters passes validation, then fails at the database layer
(oc_share.token is varchar(32)) with a raw SQL exception instead of
a clear validation error.

Add a max-length check matching the column size, and mention the
limit in the existing error message.

Assisted-by: ClaudeCode:claude-sonnet-4-6
Signed-off-by: Amit Mishra <amit.mishra.eee21@itbhu.ac.in>
refactor: Avoid calling mb_strlen twice

Co-authored-by: Josh <josh.t.richards@gmail.com>

Signed-off-by: Carl Schwan <carl@carlschwan.eu>

[skip ci]
@MiMoHo

MiMoHo commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

This backport has been a draft since June 30. Apart from the milestone moving from 33.0.7 to 33.0.10, nothing has happened since. Meanwhile the stable34 backport (#61676) was merged on July 1 and ships in 34.0.2, and the fix is in 35.

The bot warned that this backport differs from the original, and it does: it only carries the controller change, while the test from #61630 is missing. stable33 is supported until February 2027, so 33 users will keep running into #61416 (over-length custom tokens failing silently) until someone finishes this.

I have prepared a branch with both original commits hand-selected onto current stable33, including the test: stable33...MiMoHo:nextcloud-server:backport/61630/stable33-with-tests. The only conflict was in the test file, because stable33 has no Talk helper. The full ShareAPIControllerTest passes. I'm happy to open it as a replacement PR if that helps.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews AI assisted bug community pull requests from community feature: sharing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants