mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-04-26 09:46:00 +03:00
[PR #2073] [MERGED] Fix conflict resolution logic for read_only and hide_passwords flags #3050
Labels
No labels
SSO
Third party
better for forum
bug
bug
documentation
duplicate
enhancement
future Vault
future Vault
future Vault
good first issue
help wanted
low priority
notes
pull-request
question
troubleshooting
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vaultwarden#3050
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/dani-garcia/vaultwarden/pull/2073
Author: @jjlin
Created: 10/29/2021
Status: ✅ Merged
Merged: 11/1/2021
Merged by: @dani-garcia
Base:
main← Head:fix-access-logic📝 Commits (1)
6cbb724Fix conflict resolution logic forread_onlyandhide_passwordsflags📊 Changes
1 file changed (+24 additions, -21 deletions)
View changed files
📝
src/db/models/cipher.rs(+24 -21)📄 Description
For one of these flags to be in effect for a cipher, upstream requires all of
(rather than any of) the collections the cipher is in to have that flag set.
Also, some of the logic for loading access restrictions was wrong. I think
that only malicious clients that also had knowledge of the UUIDs of ciphers
they didn't have access to would have been able to take advantage of that.
Fixes #2072.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.