FeatureFuel
0

Protect uploaded documents behind auth token instead of having them publicly accessible

Source: invoiceninja/invoiceninja#8552 · opened by @CodeShakingSheep
What version of Invoice Ninja are you running? 5.5.124 What environment are you running? VPS - Native installation (no docker) running with nginx Have you searched existing issues/requests? Yes Screenshots In the screenshot I access a test png file which I uploaded to an expense's documents before in an incognito window in which I am not logged in. As shown the image is loaded when I would have expected the image not to be publicly accessible, e.g. with a redirect to the login page or a custom error message prompting the user to login. ![image]( Additional context I had a brief exchange with @turbo124 about this in the forum and he told me this is current design and that the only safety measure is that a user needs to know the hash (which I hid behind blue color in my screenshot). From my side I wasn't aware that uploaded documents would be publicly accessible. So, also I would appreciate a short hint for a user about this when he uploads a document th…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests