Providing a wrong share address template generates error 500 instead of 404

Bug #396998 reported by bgerlich
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu One Servers
Triaged
Low
Philip Fibiger

Bug Description

When requesting a share with an erroneous address, for example https://ubuntuone.com/files/shareoffer/11199629-db55-4b9e-8fa2-494ec75ebb instead of https://ubuntuone.com/files/shareoffer/11199629-db55-4b9e-8fa2-494ec75ebbaf/
, omitting last chars is a common copy/paste mistake, the server answers with error 500, when it should give 404.

Tags: ops+
Revision history for this message
Rick McBride (rmcbride) wrote :

Throwing "Denied" instead of "not found" for a mis-pasted url isn't very helpful to the pasting user.

However throwing "Denied" for every share address not specifically allowed for the user making the connection does prevent scanning for valid share IDs by an attacker, or at least make it much more difficult.

Perhaps our 500 template could be revised to suggest that mis-copied addresses could be one reason for the failed request?

Changed in ubuntuone-client:
assignee: nobody → Philip Fibiger (pfibiger)
status: New → Confirmed
status: Confirmed → Triaged
dobey (dobey)
affects: ubuntuone-client → ubunet
Changed in ubunet:
importance: Undecided → Low
tags: added: ops+
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.