Add authentication to media file serving #3
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
offsite.guru/textze#3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Media files are served via
/media/{user_id}/{filename}without any authentication. Currently relies on UUID filenames being unguessable as a security measure.Should require a valid API token to access media. This depends on the Android app passing tokens (see #2), since media URLs are loaded in image views.
Labels
server, android