nilsteampassnet / TeamPass

Collaborative Passwords Manager
https://www.teampass.net
1.65k stars 537 forks source link

Personal Folder is sometimes visible for others #1894

Closed benjamin2501 closed 1 year ago

benjamin2501 commented 7 years ago
### Steps to reproduce 1. Sadly I don't know exactly how to reproduce :( 2. I created a Ldap local User 3. Login with _lokal_ldap_user_new_ 4. set PSK for _lokal_ldap_user_new_ 5. Login with any user e.g. _lokal_ldap_user5_ ### Expected behaviour _lokal_ldap_user5_ can't see the personal folder from _lokal_ldap_user_new_ ### Actual behaviour _lokal_ldap_user5_ is able to see the personal folder from _lokal_ldap_user_new_ , his own personal folder, and folders he is able to see. _lokal_ldap_user5_ can also set his own PSK and create an Item inside of the pesonal area of _lokal_ldap_user_new_ ### Server configuration **Teampass version:** 2.1.27.7 **Updated from an older Teampass or fresh install:** upgraded ------------------------------------------------------------ This is inside the database: _teampass_roles_values_ ![grafik](https://user-images.githubusercontent.com/27355139/30029289-f7d1004c-9188-11e7-87d6-62724da998ac.png) folder_id: 180 is the id of the personal folder from _lokal_ldap_user_new_ ------------------------------------------------------------ The strange thing is, i tried to reproduce this, but my next try won't work :(
jronzon commented 6 years ago

Hello, I had the same issue but impossible to reproduce this. version 2.1.27.5

benjamin2501 commented 6 years ago

@nilsteampassnet: Bug still exists in 2.1.27.8

The _local_ldapuser5 is able to write into the personalfolder of _local_ldap_usernew the good thing is that _local_ldap_usernew isn't able the read this entry