Security Issue: File can be downloaded without permission
Dears,
Per the "Previewer" role definition the user can not download the file, only see the preview of the file.
Actually it seems it is supereasy to download the file if you copy the url of content?preview=true....... initator pdf.min.js:631 type: fetch.
I hope this helps, pls let me know if you need more deatils.
Thanks!
Csaba
1
vote
Anonymous
shared this idea