Skip to content

[stable33] Only mask the permissions for the users home directory for public shares - #59552

Merged
CarlSchwan merged 2 commits into
stable33from
backport/59511/stable33
Apr 15, 2026
Merged

[stable33] Only mask the permissions for the users home directory for public shares#59552
CarlSchwan merged 2 commits into
stable33from
backport/59511/stable33

Conversation

@backportbot

@backportbot backportbot Bot commented Apr 9, 2026

Copy link
Copy Markdown

Backport of #59511

Warning, This backport's changes differ from the original and might be incomplete ⚠️

Todo

  • Review and resolve any conflicts
  • Review and verify the backported changes
  • Amend HEAD commit to remove the line stating to skip CI

Learn more about backports at https://docs.nextcloud.com/server/stable/go.php?to=developer-backports.

Signed-off-by: Robin Appelman <robin@icewind.nl>
@backportbot backportbot Bot added the 3. to review Waiting for reviews label Apr 9, 2026
@backportbot backportbot Bot added this to the Nextcloud 33.0.3 milestone Apr 9, 2026
…c shares

fix: only mask the permissions for the users home directory for public shares

this ensures that versions/trashbin/etc is still usable

Signed-off-by: Robin Appelman <robin@icewind.nl>
Signed-off-by: Carl Schwan <carlschwan@kde.org>
@CarlSchwan
CarlSchwan force-pushed the backport/59511/stable33 branch from 7ac5ea3 to bbc1030 Compare April 9, 2026 23:56
@CarlSchwan
CarlSchwan marked this pull request as ready for review April 9, 2026 23:57
@CarlSchwan
CarlSchwan requested a review from a team as a code owner April 9, 2026 23:57
@CarlSchwan
CarlSchwan requested review from ArtificialOwl, leftybournes and provokateurin and removed request for a team April 9, 2026 23:57
@CarlSchwan
CarlSchwan merged commit 59b9ef6 into stable33 Apr 15, 2026
232 of 268 checks passed
@CarlSchwan
CarlSchwan deleted the backport/59511/stable33 branch April 15, 2026 13:09
patrickdmrezende added a commit to avuz-conecta/avuz-server that referenced this pull request Aug 27, 2026
Point upgrade 33.0.0 -> 33.0.8. Brings the native fix for chunked upload
via public file-drop links on S3 primary storage (NotPermittedException on
the assembly MOVE): DirPermissionsMask masks only the users files/ home,
leaving uploads/ unmasked, and its rename() allows the assembly when source
is deletable. Upstream nextcloud/server nextcloud#59511 + nextcloud#59654, backported to
stable33 as nextcloud#59552 + nextcloud#60240 (shipped 33.0.4). Removes the need for an Avuz
overlay for this bug.

Conflict resolution:
- 3rdparty: pinned to v33.0.8 gitlink (Composer autoloader must match NC).
- dist/files-main.js(.map): took v33.0.8; the image rebuilds dist from
  source at build (Dockerfile npm ci + npm run build), so committed dist is
  a throwaway artifact.

Verified surviving: 3 core source patches (files hide-webdav, upload-leave
warning), spreed chunked-recording overlay sentinel, avuz_theme EMailTemplate
subclass (parent unchanged in 33.0.8), themes/avuz. No source-level conflicts
with any Avuz customization (upgrade-scan: 0 conflicts).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants