You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Landscape profile images are accessible without authentication, even for private landscapes.
Steps To Reproduce
Go to a landscape profile that is not accessible without logging into Terraso
Right click the profile image and select "Copy image link" (or whatever your browser calls this action)
Open a private tab where you are not logged into Terraso, and paste that link
Expected behavior
The image should return a 404.
Actual behavior
The image appears.
Additional context
We should in fixing this issue review how we are managing access control on all of our static files so this doesn't happen unexpectedly with future potentially private data.
The text was updated successfully, but these errors were encountered:
Description
Landscape profile images are accessible without authentication, even for private landscapes.
Steps To Reproduce
Expected behavior
The image should return a 404.
Actual behavior
The image appears.
Additional context
We should in fixing this issue review how we are managing access control on all of our static files so this doesn't happen unexpectedly with future potentially private data.
The text was updated successfully, but these errors were encountered: