fix: allow copy or move on ownerless mounts when no new shares are added - #64869
salmart-dev wants to merge 2 commits into
Conversation
Signed-off-by: Salvatore Martire <4652631+salmart-dev@users.noreply.github.com>
This commit allows the move or copy operation inside ownerless mounts, when the user performing the operation has no sharing permissions and the operation would not result in exposing the files into additional shares. Signed-off-by: Salvatore Martire <4652631+salmart-dev@users.noreply.github.com> Assisted-by: ClaudeCode:claude-opus-5.5
|
/backport to stable35 |
|
/backport to stable34 |
|
/backport to stable33 |
Not sure about this, it moving a file out of a share should probably also require share permission in this case. Alternatively it should require delete permission on the source node, as moving a file out of a share is effectively deleting it for the share recipients. Not sure which one is the better solution, maybe it should even require both (as does moving a file into a share, since that requires create+share permissions). |
The logic that I followed is: the user has delete permissions on the storage, so technically they should not be denied deleting or moving a file. However, they lack the sharing permission, so they should not be able to expose data to new shares. In this context, there is nothing saying that the user should not be allowed to move files out of a share, so I would not block it. If this is a use-case we want to support, we should then put it into a feature request. |
Summary
Currently, when a user with no sharing permissions tries to move files inside a mount which has also been shared by other users, the move is blocked in all cases. This PR changes this, so that the move or copy is allowed to happen if it would result in the file not being exposed into additional shares than the current ones.
UX Notes:
Technical Note: initially I wanted to use the mounts table for this, but unfortunately in the situation where a mount already exists and the share is a group share (or any share that does not clear the user's mount cache) it results in the fix working only once the full file-system setup is triggered.
Checklist
3. to review, feature component)stable32)AI (if applicable)