attachments authentication #3579
Replies: 4 comments 5 replies
-
Hi @marco-santulli. Thank you for reporting this. It's a bug. We will get it fixed asap. |
Beta Was this translation helpful? Give feedback.
-
Hi, Actually I think that it is good that they can be made publicly accessible, for several reasons. Sometimes we want to show a user (who is not authenticated) their own documents, or in my case, I want to be able to download validated documents through a http request. For what it's worth :) |
Beta Was this translation helpful? Give feedback.
-
Hi! Wondering what the status is on this. I agree a public option would be great! The fact that all files are now stored on a publicly accessible URL is a big security risk |
Beta Was this translation helpful? Give feedback.
-
Where can I obtain the URL after uploading the file? |
Beta Was this translation helpful? Give feedback.
-
Hi,
for what I can see right now, attachments are accessible via a URL that is publicly exposed. I was expecting that URL to require authentication, but the attachment becomes publicly accessible with a URL of this type:
https://MYSERVER/prod-budi-app-assets/app_80a7651c53204a32894897bb39d7c615/attachments/a0b8a083-8604-4ef6-8714-7fe0829f1fc8.pdf
M
Beta Was this translation helpful? Give feedback.
All reactions