Implemented
0
Protect uploaded documents behind auth token instead of having them publicly accessible
Source: invoiceninja/invoiceninja#8552 · opened by @CodeShakingSheep
What version of Invoice Ninja are you running? 5.5.124 What environment are you running? VPS - Native installation (no docker) running with nginx Have you searched existing issues/requests? Yes Screenshots In the screenshot I access a test png file which I uploaded to an expense's documents before in an incognito window in which I am not logged in. As shown the image is loaded when I would have expected the image not to be publicly accessible, e.g. with a redirect to the login page or a custom error message prompting the user to login. . From my side I wasn't aware that uploaded documents would be publicly accessible. So, also I would appreciate a short hint for a user about this when he uploads a document th…
No pledges yet. Be the first to back this.
Comments
Similar requests
Expansion of export for expenses to include attached documents
0 votes · 0 comments
Feature Request: Filter by Invoice Date in API
2 votes · 0 comments
Encrypted PDF attachments Feature + Email attachment Issues of more than one company
0 votes · 0 comments
Documents with .msg extension cause error
0 votes · 0 comments
Document export capped at 100 entries
0 votes · 0 comments
No comments yet.