Skip to content

[BUG] Download with an unprivileged account #349

@aeiou8668

Description

@aeiou8668

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

It's very easy to download a PDF file with an account that doesn't have download permissions.

Expected Behavior

PDF files should not be available for download to accounts that don't have download permissions.

Steps To Reproduce

  1. Sign in with an account that doesn't have download permissions
  2. Launch View on Web
  3. launch Chrome Developer Tools
  4. select the PDF item in the Network tab and right-click to open in a new window
  5. check View PDF on Web behavior with the same permissions as an administrator

Environment

- OS: Synology NAS
- How docker service was installed: Synology Container Manager

CPU architecture

x86-64

Docker creation

N/A

Container logs

N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions