Skip to content

Fix vgrid share access with wsgidav-4.3.5+ - #689

Merged
jonasbardino merged 1 commit into
nextfrom
fix/webdavs-vgrid-share-symlink-access-on-latest-wsgidav
Oct 1, 2026
Merged

jonasbardino merged 1 commit into
nextfrom
fix/webdavs-vgrid-share-symlink-access-on-latest-wsgidav

Conversation

@jonasbardino

Copy link
Copy Markdown
Contributor

Enable follow_symlinks option in daemon_conf and pass it through the MiGFilesystemProvider constructor call to re-enable access to symlinked vgrid shared folders with wsgidav-4.3.5+, where it broke along with the security fix for:
GHSA-wm65-64rq-rh8r

The follow_symlinks option is documented at
https://wsgidav.readthedocs.io/en/latest/user_guide_configure.html
and used as explained on
https://wsgidav.readthedocs.io/en/4.3.5/_autosummary/wsgidav.fs_dav_provider.FilesystemProvider.html#wsgidav.fs_dav_provider.FilesystemProvider

We already implement and enforce our own chrooting of the symlinked paths, so the fixed issue should not matter in our setup.

Apply a few trivial lint fixes while at it.

`MiGFilesystemProvider` constructor call to re-enable access to linked vgrid
shared folders with wsgidav-4.3.5+ where it broke due to a security fix for:
GHSA-wm65-64rq-rh8r

We already implement and enforce our own chrooting of the symlinked paths so
the fixed issue should not matter in our setup.

Apply a few trivial lint fixes while at it.
@jonasbardino jonasbardino self-assigned this Oct 1, 2026
@jonasbardino jonasbardino added bug Something isn't working battle-tested Code was tested to be fully functional in line with project code guidelines. labels Oct 1, 2026
@jonasbardino jonasbardino linked an issue Oct 1, 2026 that may be closed by this pull request
@jonasbardino

Copy link
Copy Markdown
Contributor Author

The failed actions are duplicate of unrelated lint issues in #338 .

@jonasbardino
jonasbardino requested review from a team October 1, 2026 13:46
@jonasbardino jonasbardino added the stale check errors Linting/CI errors are stale old issues not caused by this PR and will be fixed elsewhere. label Oct 1, 2026
@rasmunk

rasmunk commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

A small thing, the link provided by https://wsgidav.readthedocs.io/en/4.3.5/_autosummary/wsgidav.fs_dav_provider.FilesystemProvider.html#wsgidav.fs_dav_provider.FilesystemProvider does not appear to be stable for a particular version such as 4.3.5, instead either 'latest' or 'stable' can be used such as https://wsgidav.readthedocs.io/en/stable/_autosummary/wsgidav.fs_dav_provider.FilesystemProvider.html

@Martin-Rehr Martin-Rehr left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@jonasbardino

Copy link
Copy Markdown
Contributor Author

A small thing, the link provided by https://wsgidav.readthedocs.io/en/4.3.5/_autosummary/wsgidav.fs_dav_provider.FilesystemProvider.html#wsgidav.fs_dav_provider.FilesystemProvider does not appear to be stable for a particular version such as 4.3.5, instead either 'latest' or 'stable' can be used such as https://wsgidav.readthedocs.io/en/stable/_autosummary/wsgidav.fs_dav_provider.FilesystemProvider.html

Alright, I manually pointed to that version to avoid silent version slip, but thanks for pointing it out.

@jonasbardino
jonasbardino merged commit 7017cba into next Oct 1, 2026
9 of 11 checks passed
@jonasbardino
jonasbardino deleted the fix/webdavs-vgrid-share-symlink-access-on-latest-wsgidav branch October 1, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

battle-tested Code was tested to be fully functional in line with project code guidelines. bug Something isn't working stale check errors Linting/CI errors are stale old issues not caused by this PR and will be fixed elsewhere.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WebDAVS not showing workgroup-shared files

3 participants