blocked all nextcloud requests in demo mode to stop fake-credential logins tripping brute-force protection

This commit is contained in:
2026-09-27 21:40:55 +02:00
parent c455bb1cae
commit eddd294a34
6 changed files with 55 additions and 3 deletions
@@ -3,6 +3,8 @@ import 'package:nextcloud/nextcloud.dart';
import '../../../model/endpoint_data.dart';
import '../../../session/session_manager.dart';
import '../../api_response.dart';
import '../../demo/demo_mode.dart';
import '../../errors/network_exception.dart';
abstract class WebdavApi<T> {
T genericParams;
@@ -18,6 +20,14 @@ abstract class WebdavApi<T> {
/// changes (app password minted/renewed, account switch) so it never keeps
/// authenticating with stale credentials.
static Future<WebDavClient> get webdav {
// The WebDAV client talks dart:io directly, past DemoHttpClient.
if (DemoMode.active) {
return Future.error(
NetworkException.demoBlocked(
Uri.parse(EndpointData().nextcloud().origin()),
),
);
}
// Keyed by user too: two accounts may share a password (no app password
// minted), and the client would keep the previous login name.
final nextcloud = SessionManager().requireNextcloud();