Can anyone access filenames via WebDAV?


#1

Steps to reproduce

  1. Open "Finder" on a Mac and select "Connect to Server"
  2. Add WebDAV address of ownCloud install as server adress (without adding /dav/files/USERNAME/ to the end)
  3. When I connect all the files of my main/first account are displayed (I can't open them but they are visible)

Expected behaviour

Tell us what should happen

Actual behaviour

Tell us what happens instead

PHP version: 7.1
ownCloud version: 10.0.3
Updated from an older ownCloud or fresh install: updated form older


#2

Hi,

can you specify your question?


#3

Hi!

If someone knows my ownCloud Domain. He can connetct to the server with the WebDAV URL on a Mac. By not adding /dav/files/USERNAME/ to the end he can see the file names and directories and brows them.
All without putting in any username or password.

Is that normal or can I prohibit this somehow?

thanks :slight_smile:


#4

Can you give us the full URL you entered ( hide the hostname if you want)?

Did you store your user credentials in the MAC Keychain?


#5

hm, maybe verify against demo.owncloud.org ...