Handlingar
Features #61
öppen
CA
Features #20: P1 — Community experience and polish
[P1] Protected media access is a hard security requirement
Features #61:
[P1] Protected media access is a hard security requirement
Status:
Planned
Prioritet:
Normal
Tilldelad:
-
Startdatum:
2026-08-29
Deadline:
% Klart:
10%
Beräknad tid:
Reported by:
Beskrivning
Imported from the pre-Redmine CookieMonsters TODO during the 2026-08-29 migration.
Original priority: P1 — Community experience and polish
- Protected media access is a hard security requirement:
- uploaded originals, previews and thumbnails must NOT live in a publicly readable static uploads directory;
- every media request must pass through authenticated server-side authorization that checks the current user against the image/folder's effective permission before returning bytes;
- never rely on a hidden URL, an unguessable filename or frontend-only checks as access control;
- copying an image URL must not bypass permissions: e.g. a FRIENDS image opened without an authenticated eligible friend session must return 401/403 rather than the image;
- direct URLs must remain permission-gated even when pasted into another browser, incognito window or external site;
- do not expose long-lived bearer-style image URLs that grant access merely to whoever possesses the link;
- ensure caches/CDNs cannot accidentally make restricted media public; restricted media responses should use private/non-public caching rules;
- authorization must be checked for both the displayed thumbnail and the full/original image, not only the surrounding page.
CM-TODO-ID:7fcf54be7d01ce99180e
Future notes, acceptance criteria and status changes belong in this Redmine issue.
Handlingar