Found while reviewing the beta release PR #1026 (head ae22b32).
The maintenanceWindow schema in lib/Settings/softwarecatalogus_register.json has "read": ["public"], and its new notifyUserIds property has no property-level authorization. visible: false only hides it in the UI, not in the API.
Impact: any anonymous API reader gets the Nextcloud user ids of the business and technical owners of every usage of the product. MaintenanceRecipientService resolves these with _rbac: false, _multitenancy: false across all organisations, so this exposes exactly what register.d/publication-field-rules.json keeps behind authenticated (usage.businessOwner / technicalOwner), and reveals which municipalities use a product even when their usages are unpublished.
Verification:
python3 -c "import json;s=json.load(open('lib/Settings/softwarecatalogus_register.json'))['components']['schemas']['maintenanceWindow'];print(s['authorization']['read'], s['properties']['notifyUserIds'].get('authorization'))"
→ ['public'] None
Suggested fix: add "authorization": {"read": ["software-catalog-admins"]} (or the narrowest group the notification engine needs) to notifyUserIds, and gate recipientsResolvedAt the same way.
Related (posted as a review comment on #1026): the window's own organisation can also write notifyUserIds / recipientsResolvedAt over the API, and recordRecipients() never checks that the window's author owns the module.
Found while reviewing the beta release PR #1026 (head
ae22b32).The
maintenanceWindowschema inlib/Settings/softwarecatalogus_register.jsonhas"read": ["public"], and its newnotifyUserIdsproperty has no property-levelauthorization.visible: falseonly hides it in the UI, not in the API.Impact: any anonymous API reader gets the Nextcloud user ids of the business and technical owners of every usage of the product.
MaintenanceRecipientServiceresolves these with_rbac: false, _multitenancy: falseacross all organisations, so this exposes exactly whatregister.d/publication-field-rules.jsonkeeps behindauthenticated(usage.businessOwner/technicalOwner), and reveals which municipalities use a product even when their usages are unpublished.Verification:
Suggested fix: add
"authorization": {"read": ["software-catalog-admins"]}(or the narrowest group the notification engine needs) tonotifyUserIds, and gaterecipientsResolvedAtthe same way.Related (posted as a review comment on #1026): the window's own organisation can also write
notifyUserIds/recipientsResolvedAtover the API, andrecordRecipients()never checks that the window's author owns the module.