Problem

When executing a full export
/admin/config/development/configuration/full/export
the temporary file "TEMPDIR/config.tar.gz" remains on the server, readable for everyone

michael@michael:/tmp$ ls -l conf*
-rw-r--r-- 1 michael www-data 33801 Okt 13 10:12 config.tar.gz
-rw-r--r-- 1 michael michael  33801 Okt 13 10:12 config-SITENAME-dev-bk-2015-10-13-08-12.tar.gz

btw. the timestamp of the downloaded file is UTC not localtime. I'm not sure which is the best solution, personally I would prefer a localtimestamp.

Proposed resolution

The temporary file should be deleted when download has been finished.
Propably the temporary filename should be unique, so that two Drupal8-installation on the same server will not collide

User interface changes

None

Comments

mmbk created an issue.