Skip to content
This repository has been archived by the owner on Aug 11, 2021. It is now read-only.

Password protection for already shared links insecure #4

Open
4miners opened this issue Dec 26, 2020 · 0 comments
Open

Password protection for already shared links insecure #4

4miners opened this issue Dec 26, 2020 · 0 comments

Comments

@4miners
Copy link

4miners commented Dec 26, 2020

Expected behavior

When enabling password protection for a shared link user can expect that access to that link (which may have already been shared) would require the password.

Actual behavior

This behavior is not entirely true, as links are shared with a default password (included after a hashtag), so everyone who has the sharing link already has the password too. This can be misleading for users and is a potential vulnerability.

Steps to reproduce

  • Select a file, enable sharing for it, this will generate the link with a password included after a hashtag.
    obraz
  • Share the link with some people.
  • Enable password protection for that link.
    obraz
  • People who have the first link (with hashtag) still have the access to the file, as the password is the same by default.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant