Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Thumbnailer allows generating thumbnails for images shared as secure view only #9249

Closed
butonic opened this issue May 24, 2024 · 8 comments
Closed
Labels
Priority:p2-high Escalation, on top of current planning, release blocker Type:Bug

Comments

@butonic
Copy link
Member

butonic commented May 24, 2024

When an image is shared in view only mode it should not be possible to fetch a thumbnail for it. Or not without a watermark.

@kulmann kulmann added the Priority:p2-high Escalation, on top of current planning, release blocker label May 24, 2024
@tbsbdr
Copy link
Contributor

tbsbdr commented May 27, 2024

secureview should not generate a thumbnail.

@AlexAndBear
Copy link
Contributor

Not only images but as well txt files, which makes it even more critical

@dragonchaser
Copy link
Member

dragonchaser commented Jun 4, 2024

@AlexAndBear with PR #9299 txt-files got accidentally fixed aswell 😆
The side-effect of this is, that you can no longer open files that are shared with secure-view when you do not have an active collabora running....

@dragonchaser
Copy link
Member

image

@mmattel
Copy link
Contributor

mmattel commented Jun 4, 2024

@tbsbdr after a discussion with @dragonchaser I propose that we add a small info into the thumbnail readme that thumbnails will return a 403 (forbidden) for a thumbnail request that belongs to a secure view shared object when the share reciever accessses the data. we already have such info for 404 (unavailable) and too many requests (429). this readme change should directly go into the corresponding (and currently open) PR, see: #9299. pls advice.

@AlexAndBear
Copy link
Contributor

image

Nice, but with latest web master, we don't even request the thumbnails anymore when secure view is active, so this is more a security feature for attacks or somthing

@dragonchaser
Copy link
Member

@AlexAndBear I was not aware of that, but that change would be needed anyway. Otherwise someone could craft a thumbnail link for a certain file and read the contents (as you said security...)

@AlexAndBear
Copy link
Contributor

Yeah, just wanted to update all people here in the ticket, so no one is under the impression web is still requesting endpoints, that should not be requested ;)

@dragonchaser dragonchaser removed their assignment Jun 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Priority:p2-high Escalation, on top of current planning, release blocker Type:Bug
Projects
Archived in project
Development

No branches or pull requests

6 participants