-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Medium
-
Affects Version/s: None
-
Component/s: None
-
None
When you create a backup or export, it gets dumped in the temp directory. Anyone who can guess (or intercept) the filename can get hold of the file. That's bad.
When you create a backup/export (or anything else that gets served from temp), we should put some key in the session that allows that user (and that user only) to download the file.
- mentioned in
-
Page Loading...