it’s weird…
nginx log for user that can access settings:
<IPv6> - - [<timestamp>] "GET /core/js/oc.js?v=3fa891a7 HTTP/1.1" 200 8175 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, li
ke Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /settings/user HTTP/1.1" 200 15291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like Gecko)
Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /ocs/v2.php/apps/notifications/api/v2/notifications HTTP/1.1" 200 74 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWe
bKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /apps/apporder/getOrder HTTP/1.1" 200 221 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like
Gecko) Version/13.0.5 Safari/605.1.15" "-"
user that cannot access settings:
<IPv6> - - [<timestamp>] "GET /settings/user HTTP/1.1" 302 5 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Vers
ion/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /core/js/oc.js?v=3fa891a7 HTTP/1.1" 200 8175 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, li
ke Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET / HTTP/1.1" 302 5 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Sa
fari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /apps/files/ HTTP/1.1" 200 6357 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Ver
sion/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /ocs/v2.php/apps/notifications/api/v2/notifications HTTP/1.1" 200 74 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWe
bKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /apps/apporder/getOrder HTTP/1.1" 200 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like
Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /index.php/apps/richdocuments/ajax/settings.php HTTP/1.1" 200 160 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKi
t/605.1.15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "PROPFIND /remote.php/dav/files/<username>/ HTTP/1.1" 207 24637 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15
(KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /apps/systemtags/lastused HTTP/1.1" 200 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.15 (KHTML, like
Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /index.php/apps/files/ajax/getstoragestats.php?dir=%2F HTTP/1.1" 200 223 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) App
leWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /ocs/v2.php/apps/text/workspace?path=%2F HTTP/1.1" 404 31 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.1.
15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
<IPv6> - - [<timestamp>] "GET /apps/recommendations/api/recommendations HTTP/1.1" 200 370 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/605.
1.15 (KHTML, like Gecko) Version/13.0.5 Safari/605.1.15" "-"
Seems like the order of
GET /settings/user
and
GET /core/js/oc.js
might be relevant? I don’t get where the 302 redirect would come from