-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Make "Download from URL" configurable #13326
Comments
IMHO it would be sane when per default access to all private IP addresses are forbidden and admins would manually need to opt-in. Also loopback addresses should never get resolved. |
@jancborchardt FYI – this will be a switch in the config.php most likely. |
I still vote for killing this feature - tooo broken with respect to some issues:
|
That would from a security PoV really be the best option. 👍 as well. |
@jancborchardt @MTRichards What do you think about killing this feature? |
Please notice that the current implementation is dangerous and there is not really a good way we can make it behave completely secure for all deployment scenarios. See http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html for an example, this is exactly the way how apps like Prezi got hacked 🙈 |
This is the download URL direct feature? I lean towards OK, but ... |
I wonder if it’s used at all or understood. If anything it’s a very slim usecase. I’d be ok with removing it. What do you think @owncloud/designers? |
I'm fine with the removal. @MTRichards Think of a ownCloud instance that is in an internal net. With this feature you can download stuff from within this internal net. Simple use case: ownCloud in an NAT-ed network. you can access files from behind that NAT router, by using this feature. |
@MorrisJobke Thanks! I would remove it, I don't think it is a widely used use case. |
furthermore there are more elaborate apps out there afaik - https://apps.owncloud.com/content/show.php/ocDownloader+v2.2?content=150227 @nickvergessen please open a pr to kill this for oc8.1 - THX |
Make ocDownloader a recomended app in appstore? |
only if it was reviewed and we know it's properly working |
@DeepDiver1975 Who can make that review and what are the demands for getting an app approved for appstore? |
I was so free and did it myself quickly: #14652 |
The "Download from URL" feature should be configurable and allow at least the following configuration options:
The text was updated successfully, but these errors were encountered: