You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Pictures marked as private that are included in an album can be accessed by anyone if the album is shared. The picture won't show up in the web UI, but it will be included when selecting "download all pictures" (as a zip file).
How can we reproduce it?
Steps to reproduce the behavior:
Create an album and add a few pictures
Mark one picture as private
Share the album
Open the album in a private browser window
Verify that the private picture is not visible in the web UI
Download all pictures
Verify that the private picture was included
What behavior do you expect?
Private pictures should in no way be accessible when not logged in.
Can you provide us with example files for testing or screenshots?
What version you are using?
211215-93b26f19-Linux-x86_64
Any other helpful information?
The text was updated successfully, but these errors were encountered:
lastzero
changed the title
Bug: Private pictures in shared albums are included on "downloading all" pictures.
Albums: Exclude private pictures in shared albums from downloads
Jan 2, 2022
lastzero
changed the title
Albums: Exclude private pictures in shared albums from downloads
Albums: Exclude pictures in shared albums from downloads
Jan 3, 2022
Private pictures are now always excluded from downloads, as the primary use for downloads is to share them either directly or indirectly. We may introduce a more fine-grained control with multi-user support.
If I remember correctly, the album download button was added as a "quick improvement" to do someone a favor - we should have rejected it or taken more time to think it through.
What does not work as expected?
Pictures marked as private that are included in an album can be accessed by anyone if the album is shared. The picture won't show up in the web UI, but it will be included when selecting "download all pictures" (as a zip file).
How can we reproduce it?
Steps to reproduce the behavior:
What behavior do you expect?
Private pictures should in no way be accessible when not logged in.
Can you provide us with example files for testing or screenshots?
What version you are using?
211215-93b26f19-Linux-x86_64
Any other helpful information?
The text was updated successfully, but these errors were encountered: