Skip to content
Unverified Commit becde589 authored by Lukas Reschke's avatar Lukas Reschke
Browse files

Add sudo mode to enabling and disabling apps

Otherwise an administrator could bypass sudo mode by installing an app that allows RCE by design. I've by intention excluded the update endpoint from the requirement because updating apps should be as unintruisive as possible.

Not the cleanest approach by adding this to the AJAX endpoints instead of requiring a controller but for 11 this felt safer for me. We can clean this up together later then. (also the other AJAX endpoints in this folder do have the same logic)

Ref https://github.com/nextcloud/server/issues/2487



Signed-off-by: default avatarLukas Reschke <lukas@statuscode.ch>
parent 8adf6177
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment