nextcloud/apps
Arthur Schiwon bf81fa432a fix potential unwarranted memberships in nested groups from LDAP
- the issue was present only when using PHP based resolving of nested
  group members. Normally nested members are common in AD (and Samba4) and
  are resolved per LDAP_MATCHING_RULE_IN_CHAIN by default
- resolving nested members is recursive
- when the cache entry was created it happend for intermediate groups, too,
  containing members from the parent group
- the check was added to only cache the root group with its members
- a runtime cache stores intermediate ldap read results


Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
2021-12-20 09:18:59 +00:00
..
accessibility Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
admin_audit Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
cloud_federation_api Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
comments Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
contactsinteraction Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
dashboard Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
dav Carefully filter out non matching time ranges for CalDAV search 2021-12-14 13:52:56 +00:00
encryption Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
federatedfilesharing Limit more contact searches 2021-12-13 13:48:55 +01:00
federation Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
files Limit more contact searches 2021-12-13 13:48:55 +01:00
files_external list.php files are only invoked via ViewController and APIController 2021-12-02 21:32:25 +00:00
files_sharing Discard share notification for non-existing groups 2021-12-17 07:04:25 +00:00
files_trashbin list.php files are only invoked via ViewController and APIController 2021-12-02 21:32:25 +00:00
files_versions Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
lookup_server_connector Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
oauth2 Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
provisioning_api Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
settings Bump dompurify from 2.3.3 to 2.3.4 2021-12-11 16:31:23 +00:00
sharebymail Limit more contact searches 2021-12-13 13:48:55 +01:00
systemtags list.php files are only invoked via ViewController and APIController 2021-12-02 21:32:25 +00:00
testing Update to composer 2.1.11 2021-11-04 12:30:11 +01:00
theming App summary is optional 2021-11-19 14:08:55 +00:00
twofactor_backupcodes Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
updatenotification Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
user_ldap fix potential unwarranted memberships in nested groups from LDAP 2021-12-20 09:18:59 +00:00
user_status Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
weather_status Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00
workflowengine Bump core-js from 3.19.2 to 3.19.3 2021-12-11 12:59:40 +00:00