Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential Data Leak #15

Open
ttbek opened this issue Oct 17, 2018 · 0 comments
Open

Potential Data Leak #15

ttbek opened this issue Oct 17, 2018 · 0 comments

Comments

@ttbek
Copy link

ttbek commented Oct 17, 2018

I noticed that there is an option for users to share their data in the Results tab for a job on the far right of the table, which gives them a direct download link. Isn't this a security risk? The link is accessible without being logged into their account. Can this be easily disabled? Was there some option for that in the .yaml application file for this that isn't documented? I tested if it was the "download" option, and while setting download to false certainly makes it unavailable, it makes it unavailable to the user that submitted the job as well.

Or is this unavailable until they click there to share it? In which case it might be prudent to place a second button to revoke access in case a user clicks it by mistake or without understanding the link is publicly accessible.

Version: 1.30.5 (built by travis on 2018-09-14T07:42:13Z)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant