-
Suggestion
-
Resolution: Won't Fix
-
None
NOTE: This suggestion is for Confluence Cloud. Using Confluence Server? See the corresponding suggestion.
When an attachment is deleted it still appears in searches and can be accessed. This is a potential security issue if a user accidentally uploads privileged information and needs to clear it.
Removing old page versions does not fix this problem.
Purging the attachment from the space's trash does remove it from searches. After this action, an old link to the attachment produces a strange "dead end" page with a blank attachment overlay and no exit or home link. PageDisplayedFromDeletedAttachmentLink .png
I would expect that when a user deletes an attachment it becomes invisible. The action to should not require a space admin.
The page produced from an old link to a removed attachment could also be improved with a message and escape option.
- is related to
-
CONFSERVER-51854 Weird and potentially insecure attachment deletion
- Gathering Interest