Skip to content

Secure file can be open in onlyoffice #9664

@ScharfViktor

Description

@ScharfViktor

JIRA: OCISDEV-379

related #9608 (comment) and #9608 (comment)

Steps:

  • admin shares .odt file with secure view
  • einstein opens file in collabora
  • einstein manualy change url from https://host.docker.internal:9200/external-collabora/share/1.odt?shareId= to https://host.docker.internal:9200/external-onlyoffice/share/1.odt?shareId=

Expected: secure view file opens only in Collabora. fobridden- if user tries to open file in different editor
example: openning secure file in the text-editor

Screen.Recording.2024-07-22.at.11.04.59.mov

Actual:

Screen.Recording.2024-07-22.at.10.58.23.mov

secure view file also can be open using:
desktop client endpoint: https://host.docker.internal:9200/external/open-with-web/?appName=OnlyOffice&fileId=fileUUID

but cannot open for mobile:

  • POST https://host.docker.internal:9200/app/open-with-web/?fileId=ca03e420-8166-48a1-88c2-5043904246d1%24859ef8cd-4a21-42a4-a3c7-70970d4f1e5e%21dfd09209-8fc5-4aa2-bcb8-f1cb94975a64&appName=OnlyOffice
  • get response
Screenshot 2024-07-22 at 11 30 28
  • opening in CollaboraPOST https://host.docker.internal:9200/app/open-with-web/?fileId=fileUUID&appName=Collabora get same result 400 "message": "invalid view mode"

Metadata

Metadata

Labels

Type

No type

Projects

Status

Qualification

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions