-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Simple Site] .txt files are only downloadable for logged in users. [403: Access Denied] #57411
Comments
User report: 4831460-zen |
Same issue here 35360684-hc . However the user is using PDF instead and it only affects the mobile. The same issue with a simple site and after it was moved to AT. As a workaround I had them host the PDF files in Google Drive instead. |
Reported in 7873243-zen |
Support References This comment is automatically generated. Please do not edit it.
|
Reported in |
9333449-zd-a8c |
9333449-zd-a8c |
Reported in 9356040-zd-a8c |
📌 REPRODUCTION RESULTS
📌 FINDINGS/SCREENSHOTS/VIDEO 📌 ACTIONS
|
Some discussion on this: p1738598495170769-slack-C03N25JPCE4 |
The code that prevents txt's being downloaded is to prevent an exploit. The details can be seen in the code linked by Dean in the Slack link. I feel like this one should be closed since there are workarounds and doesn't feel worth the effort. But not 100% sure, @candy02058912 , what do you think? |
If so, @donalirl we will need to update the Accepted File Types support doc to sat TXT files are on Business plans and above only (which sounds so strange! ) |
@Greatdane could you please log the request here 🙏 |
I did a follow-up with Security folks p1738846788359259-slack-C02DF688P |
Quick summary
.txt
files are able to be uploaded to a WordPress.com site but they cannot be downloaded by users who are not logged in to WordPress.comThe following message is shown instead.
I tried various other file types (such as .zip and .pdf) and they can be downloaded by anybody with the link.
As
.txt
files are relatively secure, I can only assume this is a bug affecting this file type only?This only affects Simple Sites.
Steps to reproduce
.txt
file either to the Media Library or the File Block of your Simple site.403: Access Denied
error.What you expected to happen
I would expect the `.txt. file to open like any other file that is uploadable to WordPress.com
What actually happened
The file is not viewable unless logged in to a WordPress.com account.
Context
Customer report;
p2EDhh-1mg-p2
4406715-zd-woothemes
Operating System
No response
Browser
No response
Simple, Atomic or both?
Simple
Theme-specific issue?
No response
Other notes
No response
Reproducibility
Consistent
Severity
All
Available workarounds?
Yes, easy to implement
Workaround details
Host the file on a different site (such as Google Drive).
The text was updated successfully, but these errors were encountered: