Skip to content

"Access through untrusted domain" #7732

Description

@tobiasKaminsky

When having not properly setup "trusted_domains" we get on nextcloud android app only "unknown error occured".
We are calling "server/status.php" and get 400 back.
Is 400 only returned in this case, so it is safe to check for this? Or is there a more decent way to get this?

Ratio: from time to time home users approach to us and have it misconfigured. So I want to improve this a bit

Activity

  1. MorrisJobke commented on Jan 9, 2018

    @MorrisJobke
    Member

    @nickvergessen @blizzz @rullzer @ChristophWurst Do you have an idea for an API?

  2. blizzz commented on Jan 15, 2018

    @blizzz
    Member

    We are calling "server/status.php" and get 400 back.

    Cannot say or promise for sure. 400 is pretty broad.

    Would it already suffice to provide a different message to this code? "400 Untrusted Domain"?

  3. blizzz commented on Jan 15, 2018

    @blizzz
    Member

    if we go for an API it'll be a bit more invasive since the domain is tested early in base.php

  4. tobiasKaminsky commented on Jan 15, 2018

    @tobiasKaminsky
    MemberAuthor

    If possible I do not want to check for the message. But maybe an arbitrary status code is possible?

    Edit: Maybe it will even work to pass the message directly to the user. I'll have to check.

  5. rullzer commented on Jan 16, 2018

    @rullzer
    Member

    Well we check early in base php and normally we return a page. We could of cource check for the Accept header and if that is json return some static json.

    Of course this only works if you properly check status.php first?

  6. tobiasKaminsky commented on Jan 22, 2018

    @tobiasKaminsky
    MemberAuthor

    Would it already suffice to provide a different message to this code? "400 Untrusted Domain"?

    Currently when accessing /status.php we get the complete html website back.
    We are parsing the status code, and return our own string, so changing the message on server side would not be sufficient.

    If 400 is only used there, I can simply add a "translation" for 400.
    But as 400 is so generic, maybe it is better to return a new one, e.g. 455 is not in use (according to https://en.wikipedia.org/wiki/List_of_HTTP_status_codes#4xx_Client_errors)

  7. MorrisJobke commented on Jan 22, 2018

    @MorrisJobke
    Member

    Or just return a proper status.php XML/JSON with the correct error message: 😉 (using HTTP codes for this is not really good)

  8. tobiasKaminsky commented on Jan 22, 2018

    @tobiasKaminsky
    MemberAuthor

    Well, this can still be accessible via web browser (of course if misconfigured), so a proper NC error web page is still nice for regular web browser user.

  9. MorrisJobke commented on Jan 22, 2018

    @MorrisJobke
    Member

    Well, this can still be accessible via web browser (of course if misconfigured), so a proper NC error web page is still nice for regular web browser user.

    But not on the /status.php URL ;)

  10. tobiasKaminsky commented on Jan 22, 2018

    @tobiasKaminsky
    MemberAuthor

    Indeed 👍

  11. added a commit that references this issue on Jan 22, 2018
    37026d8
  12. MorrisJobke commented on Jan 22, 2018

    @MorrisJobke
    Member

    Fix is in #7991

  13. added this to the Nextcloud 14 milestone on Jan 22, 2018
  14. added a commit that references this issue on Jan 24, 2018
    986623e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions