Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

Files uploaded into chat (media) is accessible by direct link to everybody. #1716

Closed
user318 opened this issue Dec 22, 2016 · 2 comments
Closed

Comments

@user318
Copy link

user318 commented Dec 22, 2016

If file is uploaded to the chat it becomes available with such url:
https:///_matrix/media/v1/download//
And it can be downloaded by anybody. Even by unauthorised users. And of course it is not verified that user have access to the chat.
I think it should be considered an error.

@uhoreg
Copy link
Member

uhoreg commented Mar 21, 2017

Looks like a dup of #1403

@user318
Copy link
Author

user318 commented Mar 22, 2017

Yes. Closing this issue then.

@user318 user318 closed this as completed Mar 22, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants