Skip to content

[18.0][FIX] vault: inbox share form token handling and optional file - #987

Open
jans23 wants to merge 1 commit into
OCA:18.0from
Nitrokey:18.0-fix-vault-invalid-token
Open

[18.0][FIX] vault: inbox share form token handling and optional file#987
jans23 wants to merge 1 commit into
OCA:18.0from
Nitrokey:18.0-fix-vault-invalid-token

Conversation

@jans23

@jans23 jans23 commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

The frontend inbox share form showed 'Invalid token' for valid links and wrongly required a file even when a name and secret were provided.

@jans23 jans23 changed the title [FIX] vault: inbox share form token handling and optional file [18.0][FIX] vault: inbox share form token handling and optional file Aug 24, 2026
@jans23
jans23 force-pushed the 18.0-fix-vault-invalid-token branch from c53cc4b to 1acf60a Compare August 24, 2026 12:42
Comment thread vault/views/templates.xml
placeholder="Secret"
id="secret_file"
name="secret_file"
required="required"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

True this shouldn't be required here but neither should secret be required. It should be made sure that either one of those must be present. Without the required here it's not visually obvious what is missing except for the error message on submit.

  • Entering secret but not secret_file => allowed
  • Entering secret_file but not secret => allowed
  • Entering secret and secret_file => allowed
  • Entering neither secret nor secret_file => denied

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added an appropriate error message shown to the user.

Comment thread vault/controllers/main.py Outdated
inbox = request.env["vault.inbox"].sudo().find_inbox(token)
user = request.env["res.users"].sudo().find_user_of_inbox(token)
if len(inbox) == 1 and inbox.accesses > 0:
if len(inbox) == 1:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't know about this change here. I think without access it should look like the link is invalid. To we want to be verbose here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

restored as suggested.

The frontend inbox share form showed 'Invalid token' for valid links
and wrongly required a file even when a name and secret were provided.

- Resolve the recipient public key for any valid token instead of only
  when the inbox still has accesses left, so a valid link no longer
  reports 'Invalid token'. Distinguish an unknown token from a
  recipient without a key pair with clearer messages.
- Drop the hardcoded 'required' on the file input so name + secret are
  sufficient; the file remains optional (the JS still toggles the
  requirements and the server/model already accept secret or file).
@jans23
jans23 force-pushed the 18.0-fix-vault-invalid-token branch from 1acf60a to bebdc50 Compare September 2, 2026 11:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants