Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Files for work under review can be downloaded by public via direct link #5913

Closed
rjkati opened this issue Nov 15, 2022 · 2 comments · Fixed by #5921
Closed

Files for work under review can be downloaded by public via direct link #5913

rjkati opened this issue Nov 15, 2022 · 2 comments · Fixed by #5921

Comments

@rjkati
Copy link

rjkati commented Nov 15, 2022

Descriptive summary

In hyrax 4.0.0.beta2, I can download files for works under review if I am logged out and have a direct link to the file.

Expected behavior

Files for works under review should only be downloaded by users with appropriate permissions

Actual behavior

Logged out users can access files for a work under review if they have a direct link to the file

Steps to reproduce the behavior

While logged out, attempt to access:

Both of the links above should not allow access

Next, download the file for the example work: https://nurax-dev.curationexperts.com/downloads/xs55mc34x?locale=en

@gamontoya
Copy link

@dlpierce The first two bulleted cases work as expected. However, when I try to download the file from https://nurax-dev.curationexperts.com/downloads/xs55mc34x?locale=en I get the following error:

download-hyraxdev

@dlpierce
Copy link
Contributor

dlpierce commented Dec 9, 2022

That is caused by nurax missing the file app/assets/images/unauthorized.png and should not affect freshly generated hyrax applications.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
No open projects
Development

Successfully merging a pull request may close this issue.

3 participants