Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password protection of files is by-passable with the direkt link, even after link removal and file deletion #2331

Closed
ghost opened this issue Apr 28, 2020 · 1 comment

Comments

@ghost
Copy link

ghost commented Apr 28, 2020

When pwd protecting a share link it can be bypassed with the direct link the download button links to. Looks something like this:

https://cloud.domain.tld/seafhttp/files//filename

Now even worse, after deleting the share link, i can still download the file without problems using the link

Even even worse, after deleting the file from my library and clearing the trash and setting library to keep 0 history the file is still downloadable via that link.

@killing
Copy link
Member

killing commented Sep 16, 2020

https://cloud.domain.tld/seafhttp/files//filename this link can only be accessed once and after that it becomes invalid. So it's generally not a security issue.

@killing killing closed this as completed Sep 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant