-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmapbugfeature: encryption (server-side)
Description
Steps to reproduce
Install NC13.0.1
Enable default encryption module
Create account using no password send mail option.
Follow link in mail and set password
Log in
Upload file
Log out
Click "Forgot password" and specify username
Follow link in mail and Reset password
Ignore warning about data loss and Reset password again
Uploaded file is still there and accessible
Expected behaviour
Either no warning or uploaded file should not be accessible
Nextcloud version:
13.0.1
Updated from an older Nextcloud/ownCloud or fresh install:
Fresh install
Additional thoughts
I understand that the admin recovery key now is set by default to the master key and you have to run occ encryption:disable-master-key to disable it. So this could explain the "no data loss" result
But I thought I still would need to log in as admin to start the recovery process and decrypt the master-key? Is the master key accessible to anyone who dumped the file system without needing the Admin password?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmapbugfeature: encryption (server-side)