From a2867c066453ef5d94638566efee5b263f7bf345 Mon Sep 17 00:00:00 2001 From: Morris Jobke Date: Mon, 5 Dec 2016 17:09:23 +0100 Subject: [PATCH] Properly check the data dir * fixes #1364 Signed-off-by: Morris Jobke --- core/js/setupchecks.js | 5 +++-- core/js/tests/specs/setupchecksSpec.js | 2 +- lib/private/legacy/util.php | 2 ++ 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/core/js/setupchecks.js b/core/js/setupchecks.js index 4764efc035..4d2097a5b5 100644 --- a/core/js/setupchecks.js +++ b/core/js/setupchecks.js @@ -198,7 +198,8 @@ } var afterCall = function(xhr) { var messages = []; - if (xhr.status !== 403 && xhr.status !== 307 && xhr.status !== 301 && xhr.responseText !== '') { + // .ocdata is an empty file in the data directory - if this is readable then the data dir is not protected + if (xhr.status === 200 && xhr.responseText === '') { messages.push({ msg: t('core', 'Your data directory and your files are probably accessible from the Internet. The .htaccess file is not working. We strongly suggest that you configure your web server in a way that the data directory is no longer accessible or you move the data directory outside the web server document root.'), type: OC.SetupChecks.MESSAGE_TYPE_ERROR @@ -209,7 +210,7 @@ $.ajax({ type: 'GET', - url: OC.linkTo('', oc_dataURL+'/htaccesstest.txt?t=' + (new Date()).getTime()), + url: OC.linkTo('', oc_dataURL+'/.ocdata?t=' + (new Date()).getTime()), complete: afterCall, allowAuthErrors: true }); diff --git a/core/js/tests/specs/setupchecksSpec.js b/core/js/tests/specs/setupchecksSpec.js index 5b2a7881df..faa8a2bf27 100644 --- a/core/js/tests/specs/setupchecksSpec.js +++ b/core/js/tests/specs/setupchecksSpec.js @@ -103,7 +103,7 @@ describe('OC.SetupChecks tests', function() { it('should return an error if data directory is not protected', function(done) { var async = OC.SetupChecks.checkDataProtected(); - suite.server.requests[0].respond(200, {'Content-Type': 'text/plain'}, 'file contents'); + suite.server.requests[0].respond(200, {'Content-Type': 'text/plain'}, ''); async.done(function( data, s, x ){ expect(data).toEqual([ diff --git a/lib/private/legacy/util.php b/lib/private/legacy/util.php index eaa82ec870..55dc5ae7c1 100644 --- a/lib/private/legacy/util.php +++ b/lib/private/legacy/util.php @@ -1169,6 +1169,8 @@ class OC_Util { } fwrite($fp, $testContent); fclose($fp); + + return $testContent; } /**