Uploaded image for project: 'Atlassian Access'
  1. Atlassian Access
  2. ACCESS-1793

Restrict access to https://api.media.atlassian.com download to only allowed IP addresses in the configured IP allowlist

    XMLWordPrintable

Details

    Description

      Issue Summary

      Media API links for attachments within products are accessible by external users who are not authenticated on the site and are not part of the IP addresses added to the IP allowlist.

      Steps to Reproduce

      In Confluence with IP allowlist enabled for example

      1. Create a page
      2. Add some images/screenshots
      3. Open the image from the attachment section or try to download the images
      4. It will generate a request to the Media platform: https://api.media.atlassian.com/file/XXXXXXXXX/binary?client=XXXXXXXXX&token=XXXXXXXX&name=FILE-NAME.png
      5. Copy the link of the request from the browser Network Tab
      6. Try accessing it from the device that is not on the list of allowed IP addresses for the site

      Expected Results

      External users who do not have access to the site and are not part of the allowed IP addresses should not be able to see the image.

      Actual Results

      External users can see the image with the link shared.

      Workaround

      No workaround available.

      Attachments

        Issue Links

          Activity

            People

              5cd8def7e384 Kunwardeep Singh
              e32c3a85cf21 Uchechi I
              Votes:
              6 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

                Created:
                Updated: