Blame view

sources/apps/files_encryption/hooks/hooks.php 22.1 KB
03e52840d   Kload   Init
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
  <?php
  
  /**
   * ownCloud
   *
   * @author Sam Tuke
   * @copyright 2012 Sam Tuke samtuke@owncloud.org
   *
   * This library is free software; you can redistribute it and/or
   * modify it under the terms of the GNU AFFERO GENERAL PUBLIC LICENSE
   * License as published by the Free Software Foundation; either
   * version 3 of the License, or any later version.
   *
   * This library is distributed in the hope that it will be useful,
   * but WITHOUT ANY WARRANTY; without even the implied warranty of
   * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
   * GNU AFFERO GENERAL PUBLIC LICENSE for more details.
   *
   * You should have received a copy of the GNU Affero General Public
   * License along with this library.  If not, see <http://www.gnu.org/licenses/>.
   *
   */
  
  namespace OCA\Encryption;
  
  use OC\Files\Filesystem;
  
  /**
   * Class for hook specific logic
   */
  class Hooks {
  
a293d369c   Kload   Update sources to...
33
34
35
36
37
  	// file for which we want to rename the keys after the rename operation was successful
  	private static $renamedFiles = array();
  	// file for which we want to delete the keys after the delete operation was successful
  	private static $deleteFiles = array();
  
03e52840d   Kload   Init
38
39
40
41
42
43
44
45
46
47
  	/**
  	 * @brief Startup encryption backend upon user login
  	 * @note This method should never be called for users using client side encryption
  	 */
  	public static function login($params) {
  
  		if (\OCP\App::isEnabled('files_encryption') === false) {
  			return true;
  		}
  
31b7f2792   Kload   Upgrade to ownclo...
48
  
03e52840d   Kload   Init
49
50
51
  		$l = new \OC_L10N('files_encryption');
  
  		$view = new \OC_FilesystemView('/');
31b7f2792   Kload   Upgrade to ownclo...
52
53
54
55
56
57
  
  		// ensure filesystem is loaded
  		if(!\OC\Files\Filesystem::$loaded) {
  			\OC_Util::setupFS($params['uid']);
  		}
  
03e52840d   Kload   Init
58
59
60
61
  		$privateKey = \OCA\Encryption\Keymanager::getPrivateKey($view, $params['uid']);
  
  		// if no private key exists, check server configuration
  		if(!$privateKey) {
31b7f2792   Kload   Upgrade to ownclo...
62
63
  			//check if all requirements are met
  			if(!Helper::checkRequirements() || !Helper::checkConfiguration()) {
03e52840d   Kload   Init
64
65
66
67
68
69
70
71
  				$error_msg = $l->t("Missing requirements.");
  				$hint = $l->t('Please make sure that PHP 5.3.3 or newer is installed and that OpenSSL together with the PHP extension is enabled and configured properly. For now, the encryption app has been disabled.');
  				\OC_App::disable('files_encryption');
  				\OCP\Util::writeLog('Encryption library', $error_msg . ' ' . $hint, \OCP\Util::ERROR);
  				\OCP\Template::printErrorPage($error_msg, $hint);
  			}
  		}
  
03e52840d   Kload   Init
72
73
74
75
76
77
78
  		$util = new Util($view, $params['uid']);
  
  		// setup user, if user not ready force relogin
  		if (Helper::setupUser($util, $params['password']) === false) {
  			return false;
  		}
  
31b7f2792   Kload   Upgrade to ownclo...
79
  		$session = $util->initEncryption($params);
03e52840d   Kload   Init
80
81
82
  
  		// Check if first-run file migration has already been performed
  		$ready = false;
a293d369c   Kload   Update sources to...
83
84
  		$migrationStatus = $util->getMigrationStatus();
  		if ($migrationStatus === Util::MIGRATION_OPEN) {
03e52840d   Kload   Init
85
  			$ready = $util->beginMigration();
a293d369c   Kload   Update sources to...
86
87
88
89
90
  		} elseif ($migrationStatus === Util::MIGRATION_IN_PROGRESS) {
  			// refuse login as long as the initial encryption is running
  			sleep(5);
  			\OCP\User::logout();
  			return false;
03e52840d   Kload   Init
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
  		}
  
  		// If migration not yet done
  		if ($ready) {
  
  			$userView = new \OC_FilesystemView('/' . $params['uid']);
  
  			// Set legacy encryption key if it exists, to support
  			// depreciated encryption system
  			if (
  				$userView->file_exists('encryption.key')
  				&& $encLegacyKey = $userView->file_get_contents('encryption.key')
  			) {
  
  				$plainLegacyKey = Crypt::legacyDecrypt($encLegacyKey, $params['password']);
  
  				$session->setLegacyKey($plainLegacyKey);
  
  			}
  
a293d369c   Kload   Update sources to...
111
112
113
114
115
116
117
118
119
120
121
  			// Encrypt existing user files
  			try {
  				$result = $util->encryptAll('/' . $params['uid'] . '/' . 'files', $session->getLegacyKey(), $params['password']);
  			} catch (\Exception $ex) {
  				\OCP\Util::writeLog('Encryption library', 'Initial encryption failed! Error: ' . $ex->getMessage(), \OCP\Util::FATAL);
  				$util->resetMigrationStatus();
  				\OCP\User::logout();
  				$result = false;
  			}
  
  			if ($result) {
03e52840d   Kload   Init
122
123
124
125
126
127
  
  				\OC_Log::write(
  					'Encryption library', 'Encryption of existing files belonging to "' . $params['uid'] . '" completed'
  					, \OC_Log::INFO
  				);
  
a293d369c   Kload   Update sources to...
128
129
  				// Register successful migration in DB
  				$util->finishMigration();
03e52840d   Kload   Init
130
  
a293d369c   Kload   Update sources to...
131
  			}
03e52840d   Kload   Init
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
  		}
  
  		return true;
  
  	}
  
  	/**
  	 * @brief setup encryption backend upon user created
  	 * @note This method should never be called for users using client side encryption
  	 */
  	public static function postCreateUser($params) {
  
  		if (\OCP\App::isEnabled('files_encryption')) {
  			$view = new \OC_FilesystemView('/');
  			$util = new Util($view, $params['uid']);
  			Helper::setupUser($util, $params['password']);
  		}
  	}
  
  	/**
  	 * @brief cleanup encryption backend upon user deleted
  	 * @note This method should never be called for users using client side encryption
  	 */
  	public static function postDeleteUser($params) {
  
  		if (\OCP\App::isEnabled('files_encryption')) {
  			$view = new \OC_FilesystemView('/');
  
  			// cleanup public key
  			$publicKey = '/public-keys/' . $params['uid'] . '.public.key';
  
  			// Disable encryption proxy to prevent recursive calls
  			$proxyStatus = \OC_FileProxy::$enabled;
  			\OC_FileProxy::$enabled = false;
  
  			$view->unlink($publicKey);
  
  			\OC_FileProxy::$enabled = $proxyStatus;
  		}
  	}
  
  	/**
  	 * @brief If the password can't be changed within ownCloud, than update the key password in advance.
  	 */
  	public static function preSetPassphrase($params) {
  		if (\OCP\App::isEnabled('files_encryption')) {
  			if ( ! \OC_User::canUserChangePassword($params['uid']) ) {
  				self::setPassphrase($params);
  			}
  		}
  	}
  
  	/**
  	 * @brief Change a user's encryption passphrase
  	 * @param array $params keys: uid, password
  	 */
  	public static function setPassphrase($params) {
  
  		if (\OCP\App::isEnabled('files_encryption') === false) {
  			return true;
  		}
  
  		// Only attempt to change passphrase if server-side encryption
  		// is in use (client-side encryption does not have access to
  		// the necessary keys)
  		if (Crypt::mode() === 'server') {
  
31b7f2792   Kload   Upgrade to ownclo...
199
  			$view = new \OC_FilesystemView('/');
03e52840d   Kload   Init
200
  
31b7f2792   Kload   Upgrade to ownclo...
201
  			if ($params['uid'] === \OCP\User::getUser()) {
03e52840d   Kload   Init
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
  
  				$session = new \OCA\Encryption\Session($view);
  
  				// Get existing decrypted private key
  				$privateKey = $session->getPrivateKey();
  
  				// Encrypt private key with new user pwd as passphrase
  				$encryptedPrivateKey = Crypt::symmetricEncryptFileContent($privateKey, $params['password']);
  
  				// Save private key
  				Keymanager::setPrivateKey($encryptedPrivateKey);
  
  				// NOTE: Session does not need to be updated as the
  				// private key has not changed, only the passphrase
  				// used to decrypt it has changed
  
  
  			} else { // admin changed the password for a different user, create new keys and reencrypt file keys
  
  				$user = $params['uid'];
31b7f2792   Kload   Upgrade to ownclo...
222
223
  				$util = new Util($view, $user);
  				$recoveryPassword = isset($params['recoveryPassword']) ? $params['recoveryPassword'] : null;
03e52840d   Kload   Init
224
  
31b7f2792   Kload   Upgrade to ownclo...
225
226
  				if (($util->recoveryEnabledForUser() && $recoveryPassword)
  						|| !$util->userKeysExists()) {
03e52840d   Kload   Init
227
  
31b7f2792   Kload   Upgrade to ownclo...
228
229
  					$recoveryPassword = $params['recoveryPassword'];
  					$newUserPassword = $params['password'];
03e52840d   Kload   Init
230
  
31b7f2792   Kload   Upgrade to ownclo...
231
232
  					// make sure that the users home is mounted
  					\OC\Files\Filesystem::initMountPoints($user);
03e52840d   Kload   Init
233
  
31b7f2792   Kload   Upgrade to ownclo...
234
  					$keypair = Crypt::createKeypair();
03e52840d   Kload   Init
235
  
31b7f2792   Kload   Upgrade to ownclo...
236
237
238
  					// Disable encryption proxy to prevent recursive calls
  					$proxyStatus = \OC_FileProxy::$enabled;
  					\OC_FileProxy::$enabled = false;
03e52840d   Kload   Init
239
  
31b7f2792   Kload   Upgrade to ownclo...
240
241
  					// Save public key
  					$view->file_put_contents('/public-keys/' . $user . '.public.key', $keypair['publicKey']);
03e52840d   Kload   Init
242
  
31b7f2792   Kload   Upgrade to ownclo...
243
244
  					// Encrypt private key empty passphrase
  					$encryptedPrivateKey = Crypt::symmetricEncryptFileContent($keypair['privateKey'], $newUserPassword);
03e52840d   Kload   Init
245
  
31b7f2792   Kload   Upgrade to ownclo...
246
247
248
  					// Save private key
  					$view->file_put_contents(
  							'/' . $user . '/files_encryption/' . $user . '.private.key', $encryptedPrivateKey);
03e52840d   Kload   Init
249
  
31b7f2792   Kload   Upgrade to ownclo...
250
251
252
253
254
255
256
  					if ($recoveryPassword) { // if recovery key is set we can re-encrypt the key files
  						$util = new Util($view, $user);
  						$util->recoverUsersFiles($recoveryPassword);
  					}
  
  					\OC_FileProxy::$enabled = $proxyStatus;
  				}
03e52840d   Kload   Init
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
  			}
  		}
  	}
  
  	/*
  	 * @brief check if files can be encrypted to every user.
  	 */
  	/**
  	 * @param $params
  	 */
  	public static function preShared($params) {
  
  		if (\OCP\App::isEnabled('files_encryption') === false) {
  			return true;
  		}
  
  		$l = new \OC_L10N('files_encryption');
  		$users = array();
  		$view = new \OC\Files\View('/public-keys/');
  
  		switch ($params['shareType']) {
  			case \OCP\Share::SHARE_TYPE_USER:
  				$users[] = $params['shareWith'];
  				break;
  			case \OCP\Share::SHARE_TYPE_GROUP:
  				$users = \OC_Group::usersInGroup($params['shareWith']);
  				break;
  		}
  
  		$notConfigured = array();
  		foreach ($users as $user) {
  			if (!$view->file_exists($user . '.public.key')) {
  				$notConfigured[] = $user;
  			}
  		}
  
  		if (count($notConfigured) > 0) {
  			$params['run'] = false;
  			$params['error'] = $l->t('Following users are not set up for encryption:') . ' ' . join(', ' , $notConfigured);
  		}
  
  	}
  
  	/**
  	 * @brief
  	 */
  	public static function postShared($params) {
  
03e52840d   Kload   Init
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
  		// NOTE: $params has keys:
  		// [itemType] => file
  		// itemSource -> int, filecache file ID
  		// [parent] =>
  		// [itemTarget] => /13
  		// shareWith -> string, uid of user being shared to
  		// fileTarget -> path of file being shared
  		// uidOwner -> owner of the original file being shared
  		// [shareType] => 0
  		// [shareWith] => test1
  		// [uidOwner] => admin
  		// [permissions] => 17
  		// [fileSource] => 13
  		// [fileTarget] => /test8
  		// [id] => 10
  		// [token] =>
  		// [run] => whether emitting script should continue to run
  		// TODO: Should other kinds of item be encrypted too?
  
31b7f2792   Kload   Upgrade to ownclo...
324
325
326
327
  		if (\OCP\App::isEnabled('files_encryption') === false) {
  			return true;
  		}
  
03e52840d   Kload   Init
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
  		if ($params['itemType'] === 'file' || $params['itemType'] === 'folder') {
  
  			$view = new \OC_FilesystemView('/');
  			$session = new \OCA\Encryption\Session($view);
  			$userId = \OCP\User::getUser();
  			$util = new Util($view, $userId);
  			$path = $util->fileIdToPath($params['itemSource']);
  
  			$share = $util->getParentFromShare($params['id']);
  			//if parent is set, then this is a re-share action
  			if ($share['parent'] !== null) {
  
  				// get the parent from current share
  				$parent = $util->getShareParent($params['parent']);
  
31b7f2792   Kload   Upgrade to ownclo...
343
344
  				// if parent has the same type than the child it is a 1:1 share
  				if ($parent['item_type'] === $params['itemType']) {
03e52840d   Kload   Init
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
  
  					// prefix path with Shared
  					$path = '/Shared' . $parent['file_target'];
  				} else {
  
  					// NOTE: parent is folder but shared was a file!
  					// we try to rebuild the missing path
  					// some examples we face here
  					// user1 share folder1 with user2 folder1 has
  					// the following structure
  					// /folder1/subfolder1/subsubfolder1/somefile.txt
  					// user2 re-share subfolder2 with user3
  					// user3 re-share somefile.txt user4
  					// so our path should be
  					// /Shared/subfolder1/subsubfolder1/somefile.txt
  					// while user3 is sharing
  
  					if ($params['itemType'] === 'file') {
  						// get target path
  						$targetPath = $util->fileIdToPath($params['fileSource']);
  						$targetPathSplit = array_reverse(explode('/', $targetPath));
  
  						// init values
  						$path = '';
  						$sharedPart = ltrim($parent['file_target'], '/');
  
  						// rebuild path
  						foreach ($targetPathSplit as $pathPart) {
  							if ($pathPart !== $sharedPart) {
  								$path = '/' . $pathPart . $path;
  							} else {
  								break;
  							}
  						}
  						// prefix path with Shared
  						$path = '/Shared' . $parent['file_target'] . $path;
  					} else {
  						// prefix path with Shared
  						$path = '/Shared' . $parent['file_target'] . $params['fileTarget'];
  					}
  				}
  			}
  
  			$sharingEnabled = \OCP\Share::isEnabled();
  
  			// get the path including mount point only if not a shared folder
  			if (strncmp($path, '/Shared', strlen('/Shared') !== 0)) {
  				// get path including the the storage mount point
  				$path = $util->getPathWithMountPoint($params['itemSource']);
  			}
  
  			// if a folder was shared, get a list of all (sub-)folders
  			if ($params['itemType'] === 'folder') {
  				$allFiles = $util->getAllFiles($path);
  			} else {
  				$allFiles = array($path);
  			}
  
  			foreach ($allFiles as $path) {
  				$usersSharing = $util->getSharingUsersArray($sharingEnabled, $path);
  				$util->setSharedFileKeyfiles($session, $usersSharing, $path);
  			}
  		}
  	}
  
  	/**
  	 * @brief
  	 */
  	public static function postUnshare($params) {
  
03e52840d   Kload   Init
415
416
417
418
419
420
421
  		// NOTE: $params has keys:
  		// [itemType] => file
  		// [itemSource] => 13
  		// [shareType] => 0
  		// [shareWith] => test1
  		// [itemParent] =>
  
31b7f2792   Kload   Upgrade to ownclo...
422
423
424
425
  		if (\OCP\App::isEnabled('files_encryption') === false) {
  			return true;
  		}
  
03e52840d   Kload   Init
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
  		if ($params['itemType'] === 'file' || $params['itemType'] === 'folder') {
  
  			$view = new \OC_FilesystemView('/');
  			$userId = \OCP\User::getUser();
  			$util = new Util($view, $userId);
  			$path = $util->fileIdToPath($params['itemSource']);
  
  			// check if this is a re-share
  			if ($params['itemParent']) {
  
  				// get the parent from current share
  				$parent = $util->getShareParent($params['itemParent']);
  
  				// get target path
  				$targetPath = $util->fileIdToPath($params['itemSource']);
  				$targetPathSplit = array_reverse(explode('/', $targetPath));
  
  				// init values
  				$path = '';
  				$sharedPart = ltrim($parent['file_target'], '/');
  
  				// rebuild path
  				foreach ($targetPathSplit as $pathPart) {
  					if ($pathPart !== $sharedPart) {
  						$path = '/' . $pathPart . $path;
  					} else {
  						break;
  					}
  				}
  
  				// prefix path with Shared
  				$path = '/Shared' . $parent['file_target'] . $path;
  			}
  
  			// for group shares get a list of the group members
  			if ($params['shareType'] === \OCP\Share::SHARE_TYPE_GROUP) {
  				$userIds = \OC_Group::usersInGroup($params['shareWith']);
  			} else {
  				if ($params['shareType'] === \OCP\Share::SHARE_TYPE_LINK) {
  					$userIds = array($util->getPublicShareKeyId());
  				} else {
  					$userIds = array($params['shareWith']);
  				}
  			}
  
  			// get the path including mount point only if not a shared folder
  			if (strncmp($path, '/Shared', strlen('/Shared') !== 0)) {
  				// get path including the the storage mount point
  				$path = $util->getPathWithMountPoint($params['itemSource']);
  			}
  
  			// if we unshare a folder we need a list of all (sub-)files
  			if ($params['itemType'] === 'folder') {
  				$allFiles = $util->getAllFiles($path);
  			} else {
  				$allFiles = array($path);
  			}
  
  			foreach ($allFiles as $path) {
  
  				// check if the user still has access to the file, otherwise delete share key
  				$sharingUsers = $util->getSharingUsersArray(true, $path);
  
  				// Unshare every user who no longer has access to the file
  				$delUsers = array_diff($userIds, $sharingUsers);
  
  				// delete share key
  				Keymanager::delShareKey($view, $delUsers, $path);
  			}
  
  		}
  	}
  
  	/**
a293d369c   Kload   Update sources to...
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
  	 * @brief mark file as renamed so that we know the original source after the file was renamed
  	 * @param array $params with the old path and the new path
  	 */
  	public static function preRename($params) {
  		$user = \OCP\User::getUser();
  		$view = new \OC_FilesystemView('/');
  		$util = new Util($view, $user);
  		list($ownerOld, $pathOld) = $util->getUidAndFilename($params['oldpath']);
  
  		// we only need to rename the keys if the rename happens on the same mountpoint
  		// otherwise we perform a stream copy, so we get a new set of keys
  		$mp1 = $view->getMountPoint('/' . $user . '/files/' . $params['oldpath']);
  		$mp2 = $view->getMountPoint('/' . $user . '/files/' . $params['newpath']);
  		if ($mp1 === $mp2) {
  			self::$renamedFiles[$params['oldpath']] = array(
  				'uid' => $ownerOld,
  				'path' => $pathOld);
  		}
  	}
  
  	/**
03e52840d   Kload   Init
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
  	 * @brief after a file is renamed, rename its keyfile and share-keys also fix the file size and fix also the sharing
  	 * @param array with oldpath and newpath
  	 *
  	 * This function is connected to the rename signal of OC_Filesystem and adjust the name and location
  	 * of the stored versions along the actual file
  	 */
  	public static function postRename($params) {
  
  		if (\OCP\App::isEnabled('files_encryption') === false) {
  			return true;
  		}
  
  		// Disable encryption proxy to prevent recursive calls
  		$proxyStatus = \OC_FileProxy::$enabled;
  		\OC_FileProxy::$enabled = false;
  
  		$view = new \OC_FilesystemView('/');
  		$session = new \OCA\Encryption\Session($view);
  		$userId = \OCP\User::getUser();
  		$util = new Util($view, $userId);
  
a293d369c   Kload   Update sources to...
542
543
544
545
546
547
548
549
550
551
552
  		if (isset(self::$renamedFiles[$params['oldpath']]['uid']) &&
  				isset(self::$renamedFiles[$params['oldpath']]['path'])) {
  			$ownerOld = self::$renamedFiles[$params['oldpath']]['uid'];
  			$pathOld = self::$renamedFiles[$params['oldpath']]['path'];
  		} else {
  			\OCP\Util::writeLog('Encryption library', "can't get path and owner from the file before it was renamed", \OCP\Util::ERROR);
  			return false;
  		}
  
  		list($ownerNew, $pathNew) = $util->getUidAndFilename($params['newpath']);
  
03e52840d   Kload   Init
553
  		// Format paths to be relative to user files dir
a293d369c   Kload   Update sources to...
554
555
556
  		if ($util->isSystemWideMountPoint($pathOld)) {
  			$oldKeyfilePath = 'files_encryption/keyfiles/' . $pathOld;
  			$oldShareKeyPath = 'files_encryption/share-keys/' . $pathOld;
03e52840d   Kload   Init
557
  		} else {
a293d369c   Kload   Update sources to...
558
559
  			$oldKeyfilePath = $ownerOld . '/' . 'files_encryption/keyfiles/' . $pathOld;
  			$oldShareKeyPath = $ownerOld . '/' . 'files_encryption/share-keys/' . $pathOld;
03e52840d   Kload   Init
560
561
  		}
  
a293d369c   Kload   Update sources to...
562
563
564
  		if ($util->isSystemWideMountPoint($pathNew)) {
  			$newKeyfilePath =  'files_encryption/keyfiles/' . $pathNew;
  			$newShareKeyPath =  'files_encryption/share-keys/' . $pathNew;
03e52840d   Kload   Init
565
  		} else {
a293d369c   Kload   Update sources to...
566
567
  			$newKeyfilePath = $ownerNew . '/files_encryption/keyfiles/' . $pathNew;
  			$newShareKeyPath = $ownerNew . '/files_encryption/share-keys/' . $pathNew;
03e52840d   Kload   Init
568
569
570
571
572
573
574
575
  		}
  
  		// add key ext if this is not an folder
  		if (!$view->is_dir($oldKeyfilePath)) {
  			$oldKeyfilePath .= '.key';
  			$newKeyfilePath .= '.key';
  
  			// handle share-keys
a293d369c   Kload   Update sources to...
576
  			$localKeyPath = $view->getLocalFile($oldShareKeyPath);
03e52840d   Kload   Init
577
578
579
  			$escapedPath = Helper::escapeGlobPattern($localKeyPath);
  			$matches = glob($escapedPath . '*.shareKey');
  			foreach ($matches as $src) {
a293d369c   Kload   Update sources to...
580
  				$dst = \OC\Files\Filesystem::normalizePath(str_replace($pathOld, $pathNew, $src));
03e52840d   Kload   Init
581
582
583
584
585
586
587
588
589
590
591
  
  				// create destination folder if not exists
  				if (!file_exists(dirname($dst))) {
  					mkdir(dirname($dst), 0750, true);
  				}
  
  				rename($src, $dst);
  			}
  
  		} else {
  			// handle share-keys folders
03e52840d   Kload   Init
592
593
  
  			// create destination folder if not exists
a293d369c   Kload   Update sources to...
594
595
  			if (!$view->file_exists(dirname($newShareKeyPath))) {
  				$view->mkdir(dirname($newShareKeyPath), 0750, true);
03e52840d   Kload   Init
596
597
  			}
  
a293d369c   Kload   Update sources to...
598
  			$view->rename($oldShareKeyPath, $newShareKeyPath);
03e52840d   Kload   Init
599
600
601
602
603
604
605
606
607
608
609
610
611
612
  		}
  
  		// Rename keyfile so it isn't orphaned
  		if ($view->file_exists($oldKeyfilePath)) {
  
  			// create destination folder if not exists
  			if (!$view->file_exists(dirname($newKeyfilePath))) {
  				$view->mkdir(dirname($newKeyfilePath), 0750, true);
  			}
  
  			$view->rename($oldKeyfilePath, $newKeyfilePath);
  		}
  
  		// build the path to the file
a293d369c   Kload   Update sources to...
613
  		$newPath = '/' . $ownerNew . '/files' . $pathNew;
03e52840d   Kload   Init
614
615
616
617
618
619
  
  		if ($util->fixFileSize($newPath)) {
  			// get sharing app state
  			$sharingEnabled = \OCP\Share::isEnabled();
  
  			// get users
a293d369c   Kload   Update sources to...
620
  			$usersSharing = $util->getSharingUsersArray($sharingEnabled, $pathNew);
03e52840d   Kload   Init
621
622
  
  			// update sharing-keys
a293d369c   Kload   Update sources to...
623
  			$util->setSharedFileKeyfiles($session, $usersSharing, $pathNew);
03e52840d   Kload   Init
624
625
626
627
628
629
  		}
  
  		\OC_FileProxy::$enabled = $proxyStatus;
  	}
  
  	/**
31b7f2792   Kload   Upgrade to ownclo...
630
  	 * set migration status and the init status back to '0' so that all new files get encrypted
03e52840d   Kload   Init
631
632
633
634
  	 * if the app gets enabled again
  	 * @param array $params contains the app ID
  	 */
  	public static function preDisable($params) {
31b7f2792   Kload   Upgrade to ownclo...
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
  		if ($params['app'] === 'files_encryption') {
  
  			$setMigrationStatus = \OC_DB::prepare('UPDATE `*PREFIX*encryption` SET `migration_status`=0');
  			$setMigrationStatus->execute();
  
  			$session = new \OCA\Encryption\Session(new \OC\Files\View('/'));
  			$session->setInitialized(\OCA\Encryption\Session::NOT_INITIALIZED);
  		}
  	}
  
  	/**
  	 * set the init status to 'NOT_INITIALIZED' (0) if the app gets enabled
  	 * @param array $params contains the app ID
  	 */
  	public static function postEnable($params) {
  		if ($params['app'] === 'files_encryption') {
  			$session = new \OCA\Encryption\Session(new \OC\Files\View('/'));
  			$session->setInitialized(\OCA\Encryption\Session::NOT_INITIALIZED);
03e52840d   Kload   Init
653
654
655
  		}
  	}
  
a293d369c   Kload   Update sources to...
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
  	/**
  	 * @brief if the file was really deleted we remove the encryption keys
  	 * @param array $params
  	 * @return boolean
  	 */
  	public static function postDelete($params) {
  
  		if (!isset(self::$deleteFiles[$params[\OC\Files\Filesystem::signal_param_path]])) {
  			return true;
  		}
  
  		$deletedFile = self::$deleteFiles[$params[\OC\Files\Filesystem::signal_param_path]];
  		$path = $deletedFile['path'];
  		$user = $deletedFile['uid'];
  
  		// we don't need to remember the file any longer
  		unset(self::$deleteFiles[$params[\OC\Files\Filesystem::signal_param_path]]);
  
  		$view = new \OC\Files\View('/');
  
  		// return if the file still exists and wasn't deleted correctly
  		if ($view->file_exists('/' . $user . '/files/' . $path)) {
  			return true;
  		}
  
  		// Disable encryption proxy to prevent recursive calls
  		$proxyStatus = \OC_FileProxy::$enabled;
  		\OC_FileProxy::$enabled = false;
  
  		// Delete keyfile & shareKey so it isn't orphaned
  		if (!Keymanager::deleteFileKey($view, $path, $user)) {
  			\OCP\Util::writeLog('Encryption library',
  				'Keyfile or shareKey could not be deleted for file "' . $user.'/files/'.$path . '"', \OCP\Util::ERROR);
  		}
  
  		Keymanager::delAllShareKeys($view, $user, $path);
  
  		\OC_FileProxy::$enabled = $proxyStatus;
  	}
  
  	/**
  	 * @brief remember the file which should be deleted and it's owner
  	 * @param array $params
  	 * @return boolean
  	 */
  	public static function preDelete($params) {
  		$path = $params[\OC\Files\Filesystem::signal_param_path];
  
  		// skip this method if the trash bin is enabled or if we delete a file
  		// outside of /data/user/files
  		if (\OCP\App::isEnabled('files_trashbin')) {
  			return true;
  		}
  
  		$util = new Util(new \OC_FilesystemView('/'), \OCP\USER::getUser());
  		list($owner, $ownerPath) = $util->getUidAndFilename($path);
  
  		self::$deleteFiles[$params[\OC\Files\Filesystem::signal_param_path]] = array(
  			'uid' => $owner,
  			'path' => $ownerPath);
  	}
  
03e52840d   Kload   Init
718
  }