Attachments opening with https://api.media.atlassian.com are visible to external users not having access to site.

XMLWordPrintable

    • 2
    • Major

      Issue Summary

      When attachments from attachment section opened with https://api.media.atlassian.com are visible to external users not having access to site.

      Steps to Reproduce

      1. Create a page
      2. Add some images/screenshots
      3. open the image from attachment section.
      4. It should open with https://api.media.atlassian.com/file/xxxxxxxxxxxxxxxxxxxx/binary?token=name=Screenshot%202022-06-23%20at%2011.32.02%20PM.png

      Expected Results

      Users who do have access to site should not be able to see the image.

      Actual Results

      External users can see the image with the link shared.

      Workaround

      No available just yet. Once we have the workaround, we will post it here.

            Assignee:
            Pepe (Inactive)
            Reporter:
            Trupti Das
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

              Created:
              Updated:
              Resolved: