2021-02-03 07:42:56 +01:00
|
|
|
// Copyright (c) Umbraco.
|
|
|
|
|
// See LICENSE for more details.
|
|
|
|
|
|
2018-06-29 19:52:40 +02:00
|
|
|
using System.Security.AccessControl;
|
2022-06-02 08:18:31 +02:00
|
|
|
using System.Security.Principal;
|
2021-02-03 07:42:56 +01:00
|
|
|
using Microsoft.Extensions.Options;
|
2021-02-22 12:51:17 +01:00
|
|
|
using Umbraco.Cms.Core;
|
2021-02-09 10:22:42 +01:00
|
|
|
using Umbraco.Cms.Core.Configuration.Models;
|
|
|
|
|
using Umbraco.Cms.Core.Hosting;
|
|
|
|
|
using Umbraco.Cms.Core.Install;
|
|
|
|
|
using Umbraco.Cms.Core.IO;
|
2021-02-09 11:26:22 +01:00
|
|
|
using Umbraco.Extensions;
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
namespace Umbraco.Cms.Infrastructure.Install;
|
|
|
|
|
|
|
|
|
|
/// <inheritdoc />
|
|
|
|
|
public class FilePermissionHelper : IFilePermissionHelper
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
private readonly GlobalSettings _globalSettings;
|
|
|
|
|
private readonly IHostingEnvironment _hostingEnvironment;
|
|
|
|
|
private readonly IIOHelper _ioHelper;
|
|
|
|
|
|
|
|
|
|
private readonly string[] _packagesPermissionsDirs;
|
|
|
|
|
|
|
|
|
|
// ensure that these directories exist and Umbraco can write to them
|
|
|
|
|
private readonly string[] _permissionDirs;
|
|
|
|
|
|
|
|
|
|
// ensure Umbraco can write to these files (the directories must exist)
|
|
|
|
|
private readonly string[] _permissionFiles = Array.Empty<string>();
|
|
|
|
|
private readonly string _basePath;
|
|
|
|
|
|
|
|
|
|
/// <summary>
|
|
|
|
|
/// Initializes a new instance of the <see cref="FilePermissionHelper" /> class.
|
|
|
|
|
/// </summary>
|
Resolved more warnings, and marked more warning types as errors (#16991)
* Fix warnings SA1111, SA1028, SA1500, IDE1270 in Umbraco.Web.Website, and updated rules.
* Remove warnings: IDE0270: Null check can be simplified
* More SqlServer project warnings resolved
* CS0105 namespace appeared already
* Suppress warning until implementation:
#pragma warning disable CS0162 // Unreachable code detected
#pragma warning disable CS0618 // Type or member is obsolete
CS0162 remove unreachable code
SA1028 remove trailing whitespace
SA1106 no empty statements
CS1570 malformed XML
CS1572 corrected xml parameter
CS1573 param tag added
IDE0007 var not explicit
IDE0008 explicit not var
IDE0057 simplify substring
IDE0074 compound assignment
CA1825 array.empty
Down to 3479 warnings
* - SA1116, SA117 params on same line
- IDE0057 substring simplified
Specific warnings for Umbraco.Tests.Benchmarks
* Fixed IDE0074 compound assignment and added specific warnings for Umbraco.Tests.Common
* Specific warnings for Umbraco.Tests.Integration and Umbraco.Tests.Common
Fixed:
- SA1111, SA1116, SA117 params and line formatting (not all as there are many)
- SA1122 string.Empty
- IDE0057 simplify substring
- IDE0044,IDE0044 make field readonly
- IDE1006 naming rule violation (add _)
- SA1111 closing parenthesis on line of last parameter
- SA1649 filename match type name
- SA1312,SA1306 lowercase variable and field names
* Fixed various warnings where they are more straight-forward, including:
- SA1649 file name match type name
- SA111 parenthesis on line of last parameter
- IDE0028 simplify collection initializer
- SA1306 lower-case letter field
- IDE044 readonly field
- SA1122 string.Empty
- SA1116 params same line
- IDE1006 upper casing
- IDE0041 simplify null check
Updated the following projects to only list their remaining specific warning codes:
- Umbraco.Tests.UnitTests
Typo in `Umbraco.Web.Website` project
* Reverted test change
* Now 1556 warnings.
Fixed various warnings where they are more straight-forward, including:
- SA1111/SA1116/SA1119 parenthesis
- SA1117 params
- SA1312 lowercase variable
- SA1121 built-in type
- SA1500/SA1513/SA1503 formatting braces
- SA1400 declare access modifier
- SA1122 string.Empty
- SA1310 no underscore
- IDE0049 name simplified
- IDE0057 simplify substring
- IDE0074 compound assignment
- IDE0032 use auto-property
- IDE0037 simplify member name
- IDE0008 explicit type not var
- IDE0016/IDE0270/IDE0041 simplify null checks
- IDE0048/SA1407 clarity in arithmetic
- IDE1006 correct param names
- IDE0042 deconstruct variable
- IDE0044 readonly
- IDE0018 inline variable declarations
- IDE0074/IDE0054 compound assignment
- IDE1006 naming
- CS1573 param XML
- CS0168 unused variable
Comment formatting in project files for consistency.
Updated all projects to only list remaining specific warning codes as warnings instead of errors (errors is now default).
* Type not var, and more warning exceptions
* Tweaked merge issue, readded comment about rollback
* Readded comment re rollback.
* Readded comments
* Comment tweak
* Comment tweak
2024-09-24 12:56:28 +01:00
|
|
|
public FilePermissionHelper(
|
|
|
|
|
IOptions<GlobalSettings> globalSettings,
|
|
|
|
|
IIOHelper ioHelper,
|
2022-06-02 08:18:31 +02:00
|
|
|
IHostingEnvironment hostingEnvironment)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
_globalSettings = globalSettings.Value;
|
|
|
|
|
_ioHelper = ioHelper;
|
|
|
|
|
_hostingEnvironment = hostingEnvironment;
|
|
|
|
|
_basePath = hostingEnvironment.MapPathContentRoot("/");
|
|
|
|
|
_permissionDirs = new[]
|
2020-01-28 15:22:14 +01:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
hostingEnvironment.MapPathWebRoot(_globalSettings.UmbracoCssPath),
|
|
|
|
|
hostingEnvironment.MapPathContentRoot(Constants.SystemDirectories.Config),
|
|
|
|
|
hostingEnvironment.MapPathContentRoot(Constants.SystemDirectories.Data),
|
|
|
|
|
hostingEnvironment.MapPathWebRoot(_globalSettings.UmbracoMediaPhysicalRootPath),
|
|
|
|
|
hostingEnvironment.MapPathContentRoot(Constants.SystemDirectories.Preview),
|
|
|
|
|
};
|
|
|
|
|
_packagesPermissionsDirs = new[]
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
hostingEnvironment.MapPathContentRoot(Constants.SystemDirectories.Bin),
|
|
|
|
|
hostingEnvironment.MapPathContentRoot(Constants.SystemDirectories.Umbraco),
|
|
|
|
|
hostingEnvironment.MapPathContentRoot(Constants.SystemDirectories.Packages),
|
|
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/// <inheritdoc />
|
|
|
|
|
public bool RunFilePermissionTestSuite(out Dictionary<FilePermissionTest, IEnumerable<string>> report)
|
|
|
|
|
{
|
|
|
|
|
report = new Dictionary<FilePermissionTest, IEnumerable<string>>();
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
EnsureDirectories(_permissionDirs, out IEnumerable<string> errors);
|
|
|
|
|
report[FilePermissionTest.FolderCreation] = errors.ToList();
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
EnsureDirectories(_packagesPermissionsDirs, out errors);
|
|
|
|
|
report[FilePermissionTest.FileWritingForPackages] = errors.ToList();
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
EnsureFiles(_permissionFiles, out errors);
|
|
|
|
|
report[FilePermissionTest.FileWriting] = errors.ToList();
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
EnsureCanCreateSubDirectory(
|
|
|
|
|
_hostingEnvironment.MapPathWebRoot(_globalSettings.UmbracoMediaPhysicalRootPath),
|
|
|
|
|
out errors);
|
|
|
|
|
report[FilePermissionTest.MediaFolderCreation] = errors.ToList();
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
return report.Sum(x => x.Value.Count()) == 0;
|
|
|
|
|
}
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
private bool EnsureDirectories(string[] dirs, out IEnumerable<string> errors, bool writeCausesRestart = false)
|
|
|
|
|
{
|
|
|
|
|
List<string>? temp = null;
|
|
|
|
|
var success = true;
|
|
|
|
|
foreach (var dir in dirs)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
// we don't want to create/ship unnecessary directories, so
|
|
|
|
|
// here we just ensure we can access the directory, not create it
|
|
|
|
|
var tryAccess = TryAccessDirectory(dir, !writeCausesRestart);
|
|
|
|
|
if (tryAccess)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
continue;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
|
2024-09-10 15:17:29 +01:00
|
|
|
temp ??= new List<string>();
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
temp.Add(dir.TrimStart(_basePath));
|
|
|
|
|
success = false;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
errors = success ? Enumerable.Empty<string>() : temp ?? Enumerable.Empty<string>();
|
|
|
|
|
return success;
|
|
|
|
|
}
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
private bool EnsureFiles(string[] files, out IEnumerable<string> errors)
|
|
|
|
|
{
|
|
|
|
|
List<string>? temp = null;
|
|
|
|
|
var success = true;
|
|
|
|
|
foreach (var file in files)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
var canWrite = TryWriteFile(file);
|
|
|
|
|
if (canWrite)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
continue;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
|
2024-09-10 15:17:29 +01:00
|
|
|
temp ??= new List<string>();
|
2022-06-02 08:18:31 +02:00
|
|
|
|
|
|
|
|
temp.Add(file.TrimStart(_basePath));
|
|
|
|
|
success = false;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
errors = success ? Enumerable.Empty<string>() : temp ?? Enumerable.Empty<string>();
|
|
|
|
|
return success;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private bool EnsureCanCreateSubDirectory(string dir, out IEnumerable<string> errors)
|
|
|
|
|
=> EnsureCanCreateSubDirectories(new[] { dir }, out errors);
|
|
|
|
|
|
|
|
|
|
private bool EnsureCanCreateSubDirectories(IEnumerable<string> dirs, out IEnumerable<string> errors)
|
|
|
|
|
{
|
|
|
|
|
List<string>? temp = null;
|
|
|
|
|
var success = true;
|
|
|
|
|
foreach (var dir in dirs)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
var canCreate = TryCreateSubDirectory(dir);
|
|
|
|
|
if (canCreate)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
continue;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
2022-06-02 08:18:31 +02:00
|
|
|
|
2024-09-10 15:17:29 +01:00
|
|
|
temp ??= new List<string>();
|
2022-06-02 08:18:31 +02:00
|
|
|
|
|
|
|
|
temp.Add(dir);
|
|
|
|
|
success = false;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
errors = success ? Enumerable.Empty<string>() : temp ?? Enumerable.Empty<string>();
|
|
|
|
|
return success;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// tries to create a sub-directory
|
|
|
|
|
// if successful, the sub-directory is deleted
|
|
|
|
|
// creates the directory if needed - does not delete it
|
|
|
|
|
private bool TryCreateSubDirectory(string dir)
|
|
|
|
|
{
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
var path = Path.Combine(dir, _ioHelper.CreateRandomFileName());
|
|
|
|
|
Directory.CreateDirectory(path);
|
|
|
|
|
Directory.Delete(path);
|
|
|
|
|
return true;
|
|
|
|
|
}
|
|
|
|
|
catch
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// tries to create a file
|
|
|
|
|
// if successful, the file is deleted
|
|
|
|
|
//
|
|
|
|
|
// or
|
|
|
|
|
//
|
|
|
|
|
// use the ACL APIs to avoid creating files
|
|
|
|
|
//
|
|
|
|
|
// if the directory does not exist, do nothing & success
|
|
|
|
|
private bool TryAccessDirectory(string dirPath, bool canWrite)
|
|
|
|
|
{
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
if (Directory.Exists(dirPath) == false)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
return true;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
2022-06-02 08:18:31 +02:00
|
|
|
|
|
|
|
|
if (canWrite)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
var filePath = dirPath + "/" + _ioHelper.CreateRandomFileName() + ".tmp";
|
|
|
|
|
File.WriteAllText(filePath, "This is an Umbraco internal test file. It is safe to delete it.");
|
|
|
|
|
File.Delete(filePath);
|
|
|
|
|
return true;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
2022-06-02 08:18:31 +02:00
|
|
|
|
|
|
|
|
return HasWritePermission(dirPath);
|
|
|
|
|
}
|
|
|
|
|
catch
|
|
|
|
|
{
|
|
|
|
|
return false;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
2022-06-02 08:18:31 +02:00
|
|
|
}
|
2018-06-29 19:52:40 +02:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
private bool HasWritePermission(string path)
|
|
|
|
|
{
|
|
|
|
|
var writeAllow = false;
|
|
|
|
|
var writeDeny = false;
|
|
|
|
|
var accessControlList = new DirectorySecurity(
|
|
|
|
|
path,
|
|
|
|
|
AccessControlSections.Access | AccessControlSections.Owner | AccessControlSections.Group);
|
|
|
|
|
|
|
|
|
|
AuthorizationRuleCollection accessRules;
|
|
|
|
|
try
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
accessRules = accessControlList.GetAccessRules(true, true, typeof(SecurityIdentifier));
|
|
|
|
|
}
|
|
|
|
|
catch (Exception)
|
|
|
|
|
{
|
|
|
|
|
// This is not 100% accurate because it could turn out that the current user doesn't
|
|
|
|
|
// have access to read the current permissions but does have write access.
|
|
|
|
|
// I think this is an edge case however
|
|
|
|
|
return false;
|
|
|
|
|
}
|
2021-02-03 07:42:56 +01:00
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
foreach (FileSystemAccessRule rule in accessRules)
|
|
|
|
|
{
|
|
|
|
|
if ((FileSystemRights.Write & rule.FileSystemRights) != FileSystemRights.Write)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
continue;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
2022-06-02 08:18:31 +02:00
|
|
|
|
|
|
|
|
if (rule.AccessControlType == AccessControlType.Allow)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
writeAllow = true;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
2022-06-02 08:18:31 +02:00
|
|
|
else if (rule.AccessControlType == AccessControlType.Deny)
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
writeDeny = true;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2022-06-02 08:18:31 +02:00
|
|
|
return writeAllow && writeDeny == false;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// tries to write into a file
|
|
|
|
|
// fails if the directory does not exist
|
|
|
|
|
private bool TryWriteFile(string file)
|
|
|
|
|
{
|
|
|
|
|
try
|
2018-06-29 19:52:40 +02:00
|
|
|
{
|
2022-06-02 08:18:31 +02:00
|
|
|
var path = file;
|
|
|
|
|
File.AppendText(path).Close();
|
|
|
|
|
return true;
|
|
|
|
|
}
|
|
|
|
|
catch
|
|
|
|
|
{
|
|
|
|
|
return false;
|
2018-06-29 19:52:40 +02:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|