View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0003118 | SOGo | ActiveSync | public | 2015-02-27 10:33 | 2016-11-21 15:50 |
Reporter | Mathias Roland | Assigned To | ludovic | ||
Priority | urgent | Severity | major | Reproducibility | always |
Status | resolved | Resolution | fixed | ||
Product Version | 2.2.16 | ||||
Fixed in Version | 3.2.2 | ||||
Summary | 0003118: ActiveSync does not enforce permissions | ||||
Description |
| ||||
Tags | No tags attached. | ||||
Just for your information, we have a patch for this. But we're still polishing it. |
|
How long do you need to publish the patch? |
|
1 and 2 are fixed with: https://github.com/inverse-inc/sogo/commit/fc9b175f25460b870335c397b03086e347e1af5a |
|
Personal folders (calendar/contacts) are no longer synced with above fix. |
|
Try this fix: https://github.com/inverse-inc/sogo/commit/9d310237246ba79a316a4cb006368ddd53c20a87 |
|
Case 3 observed here with Android 6 native EAS. A private calendar event in my calendar is sync'd to another user with "Private: None" access. The event is not displayed in the other user's calendar in webmail or via CalDAV in Thunderbird. The record sent to the Android device contains all the details along with the tag: <Sensitivity xmlns="Calendar:">2</Sensitivity> I personally would prefer the back-end to no rely on the client failing to display something and implement the security during sync, if this is possible? |
|
sogo: master f7c44863 2016-11-21 10:45 Details Diff |
(feat) relaxed permission requirements for subscription synchronizations (fixes 0003118 and 0003180) |
Affected Issues 0003118 |
|
mod - ActiveSync/SOGoActiveSyncDispatcher+Sync.m | Diff File | ||
mod - ActiveSync/SOGoActiveSyncDispatcher.m | Diff File | ||
mod - NEWS | Diff File | ||
sogo: v2 73d663fe 2016-11-21 10:45 Details Diff |
(feat) relaxed permission requirements for subscription synchronizations (fixes 0003118 and 0003180) Conflicts: NEWS |
Affected Issues 0003118 |
|
mod - ActiveSync/SOGoActiveSyncDispatcher+Sync.m | Diff File | ||
mod - ActiveSync/SOGoActiveSyncDispatcher.m | Diff File | ||
mod - NEWS | Diff File |
Date Modified | Username | Field | Change |
---|---|---|---|
2015-02-27 10:33 | Mathias Roland | New Issue | |
2015-03-18 14:55 | ludovic | Note Added: 0008302 | |
2015-07-09 07:26 | Mathias Roland | Note Added: 0008715 | |
2015-10-20 19:35 | ludovic | Note Added: 0009016 | |
2015-10-24 08:43 | tfu | Note Added: 0009059 | |
2015-11-05 16:12 | ludovic | Note Added: 0009074 | |
2016-01-18 10:59 | Christian Mack | Relationship added | has duplicate 0003440 |
2016-05-12 19:55 | McMichaeli | Note Added: 0010132 | |
2016-11-21 15:46 | ludovic | Changeset attached | => sogo master f7c44863 |
2016-11-21 15:46 | ludovic | Assigned To | => ludovic |
2016-11-21 15:46 | ludovic | Resolution | open => fixed |
2016-11-21 15:47 | ludovic | Status | new => resolved |
2016-11-21 15:47 | ludovic | Fixed in Version | => 3.2.2 |
2016-11-21 15:47 | ludovic | Relationship added | related to 0003180 |
2016-11-21 15:50 | ludovic | Changeset attached | => sogo v2 73d663fe |