You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I am sorry if this is a duplicate, I did try to look for open issues using all the usual keywords, but without success.
So we have a private room, and in it, we shared a semi-secret document (via upload). Circumstance had it that someone accidentally leaked the URL to the scan to another forum. He immediately noticed, but there was nothing we could do, AFAICT, for knowledge of the URL would allow anyone to download the scan. One doesn't even need to be logged in to Riot/Matrix, let alone be a member of the room.
This is bad, and I'd argue that media URLs should essentially default to 403s or 401s, unless credentials are provided and those would be enough to let you see the media in Riot.
The text was updated successfully, but these errors were encountered:
I am sorry if this is a duplicate, I did try to look for open issues using all the usual keywords, but without success.
So we have a private room, and in it, we shared a semi-secret document (via upload). Circumstance had it that someone accidentally leaked the URL to the scan to another forum. He immediately noticed, but there was nothing we could do, AFAICT, for knowledge of the URL would allow anyone to download the scan. One doesn't even need to be logged in to Riot/Matrix, let alone be a member of the room.
This is bad, and I'd argue that media URLs should essentially default to 403s or 401s, unless credentials are provided and those would be enough to let you see the media in Riot.
The text was updated successfully, but these errors were encountered: