Problem/Motivation

Even when a managed file element's #uri_scheme is set to private the temp file is available to anonymous user

Steps to reproduce

  • As an anonymous user
  • Goto /form/test-element-managed-file
  • Upload a text file
  • Click link to temp file

Proposed resolution

Block anonymous users from accessing temporary private files.

Remaining tasks

  • Remove links from file upload widget to anonymous file
  • Block access to anonymous file.
  • Write tests
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

jrockowitz created an issue. See original summary.

jrockowitz’s picture

Status: Active » Needs review
FileSize
6.36 KB
jrockowitz’s picture

Issue summary: View changes

  • jrockowitz authored 341261a on 8.x-5.x
    Issue #2842640 by jrockowitz: Private temp files are still accessible to...
jrockowitz’s picture

Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.