Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

个人文件下的目录,只要获得路径就可以在其他浏览器下载,安全隐患 #229

Closed
liangdy678 opened this issue Oct 12, 2023 · 1 comment

Comments

@liangdy678
Copy link

image
我们分享或者泄露了这个地址,在其他浏览器就可以下载这个文件夹,不像分享链接,可以取消分享,这个直接裸奔,不知道是不是个安全问题?

@zicla
Copy link
Contributor

zicla commented Nov 9, 2023

感谢你的issue,该问题已经在4.0.2版本中修复了。 https://github.com/eyebluecn/tank/releases/tag/v4.0.2

因为路径中带有uuid,所以路径不会轻易猜出,但是为了安全起见,建议将存量的文件夹都设置为隐私。

UPDATE tank40_matter SET privacy = 1 WHERE dir = 1;

@zicla zicla closed this as completed Nov 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants