security bug in WebDAV shares / how to use individual credentials?

Eisbahn

Cadet
Joined
Mar 2, 2022
Messages
3
Hi TrueNAS team,

just installed your iso and created some shares, one of it is a WebDAV for calendar and contact data. At the moment I managed to get it running only with one given user having a fixed password. But that would be nonsense, as every user and device would get this pass and could modify everything having the same rights. Even if I create new and different shares, all of them have the same credentials, so it is more or less a guessing of the share name to get access to everything (e.g. private contacts, appointments...)... As we have 2022 and also the underlying system has more than the root user and roles & right management: what am I doing wrong? How could I use different privileges? How could I limit access on groups (or maybe on user) level? Or what should I do if a mobile gets lost/stolen, revoke the pass for all?
As a workaround I found the advice to use nextcloud or similar services, but it seems those do not know the users from TrueNAS and I have to create and maintain all users and groups with twice the efforts.
What am I doing wrong? Are you working on a solution, will you disable WebDAV at all in next releases, do I have to buy Enterprise functions?

Best, Hans
 
Top