-
Notifications
You must be signed in to change notification settings - Fork 32
enh(Sharing): backend infrastructre for read-only link shares #2211
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
c331e92 to
ec7bd73
Compare
| #[OpenAPI(scope: OpenAPI::SCOPE_IGNORE)] | ||
| #[FrontpageRoute(verb: 'GET', url: '/s/{token}')] | ||
| public function linkShare(string $token): TemplateResponse { | ||
| Util::addScript(Application::APP_ID, 'tables-main'); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@enjeck may keep this if new functionality goes into the main script, or otherwise we can change this if course and load a different one.
The share token is being provided via initialState a few lines below.
d0a78bc to
63b0a70
Compare
63b0a70 to
9f86cfc
Compare
lib/Service/RowService.php
Outdated
| public function formatRowsForPublicShare(array $rows): array { | ||
| return array_map(static function (Row2 $row): array { | ||
| $rowData = $row->jsonSerialize(); | ||
| unset($rowData['tableId']); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why do we unset the tableId but not the column/row ids? What makes tableId more riskier
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If we can prevent sending the row and column ids, we should do that. IIRC we need the column IDs as column meta data and rows are separate resourced and need to be linked together. Maybe we can hold back the row Id.
But if we allow to have deep/anchor links to the specific table or view row, we have to provide it i think.
The basic idea is to leak as little internal data as possible. Even if table IDs are known, without authentication and access you should not be able to do anything about them. As they are being sequential at the moment, having them withdrawn is not a big protection either.
That said, I am open to leave this item in place and send it along with the payload.
enjeck
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
we don't seem to have a way to get the title and description of the table/view given the token?
9f86cfc to
6cc82e6
Compare
6cc82e6 to
7858b90
Compare
Indeed, those details… requires another public controller. No biggy. It would return either |
We could use initialState too if that's easier? |
Indeed 👍 It does not change much for the response type definition, but would save that additional controller, that's right. |
6ad4120 to
0078f8d
Compare
- modifies oc_tables_share structure with two columns, token and password - adds ShareOCSController with a route to create link shares - adds a PageController front route to display the link share - adds a ApiPublicColumnsController to retrieve columns for public links. It was not added to the existing ApiColumnsController, as it requires the userId of the logged-in user and I did not want to weaken this detail. - adds an abstract controller for columns with shared functionality and make ApiColumnsController extend it. - adds a PublicRowOCSController for retrieving rows through link shares - adds a ShareToken value object - adds a ShareControlMiddleware for share token and existance validation. It comes with the AssertShareToken attribute. - extends Share entity with ShareToken and Password properties - extends ShareMapper to find a share by the share token - extends ShareService with a method to easily create link shares - extends ResponseDefinitions with TablesPublicRow and TablesPublicColumn specs. Essentially tableIDs are not exposed and also user ids in lastEditBy and createdBy are not disclosed. - extends RowService and ColumnService with methods to return such ^ formatted result arrays. - extends OpenAPI spec Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
0078f8d to
28fa2e9
Compare
contributes to #67
links. It was not added to the existing ApiColumnsController, as it
requires the userId of the logged-in user and I did not want to weaken
this detail.
make ApiColumnsController extend it.
validation. It comes with the AssertShareToken attribute.
TablesPublicColumn specs. Essentially tableIDs are not exposed and
also user ids in lastEditBy and createdBy are not disclosed.
formatted result arrays.
Curl examples for added API endpoints
Create a share link without password
fetch column information
fetch all rows