haiwen / seafdav

Seafile webdav server
Other
84 stars 68 forks source link

Webdav Authentication glitch #21

Closed derflocki closed 4 years ago

derflocki commented 6 years ago

Hi!

I have just discovered a glitch in the username handling. Given the user "test@seafiltest.com" and password "testtest", it is possible to authenticate and browse via webdav, when providing a Username with trailing whitespace: e.g.: "test@seafiltest.com ". Moving, Uploading and Deleting is not possible with these credentials.

github-actions[bot] commented 4 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.