-
Notifications
You must be signed in to change notification settings - Fork 13.5k
uploaded files are not protected #16261
Copy link
Copy link
Closed
Description
Description:
After adding JWT for downloaded files, files are not protected if JWT is disabled
Steps to reproduce:
- Go to Administration -> FIle Upload
- Enable
Protect Uploaded Filesand disableEnable JWT protectionand save changes

- Upload file to room
- Open
FIles Listto the room and Copy the link of any file - Open the copied link in a new incognito browser tab
Expected behavior:
Expected 403 Forbidden
Actual behavior:
File downloaded
Server Setup Information:
- Version of Rocket.Chat Server: 2.3.0
- NodeJS Version: 8.7
- MongoDB Version: 4.0
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels