mirror of
https://github.com/hedgedoc/hedgedoc.git
synced 2026-08-07 07:14:49 +00:00
6c5b44eaec
Previously, the permission checks of the /media/:uuid route could be bypassed for the local filesystem as a media backend, because the /media/:uuid route performed a redirect to the target after checking the permissions. Since the target was always /uploads/:uuid.ext where ext was the extension of the uploaded file, you could simply try to guess the file extension and have access to the file since the /uploads endpoint was simply the complete uploads folder mounted. Now, media uploads from the local filesystem backend are served under the /media route directly instead of a redirect. Signed-off-by: Erik Michelson <github@erik.michelson.eu>