Uploaded image for project: 'Confluence Cloud'
  1. Confluence Cloud
  2. CONFCLOUD-78161

Restrict access to https://api.media.atlassian.com download to only authenticated users

    XMLWordPrintable

Details

    • Suggestion
    • Resolution: Unresolved
    • Media
    • 1
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      Issue Summary

      Media API links for attachments within products are accessible by external users who are not authenticated on the site.

      Steps to Reproduce

      1. Create a Confluence page
      2. Add some images/screenshots
      3. Open the image from the attachment section or try to download the images
      4. It will generate a request to the Media platform: https://api.media.atlassian.com/file/XXXXXXXXX/binary?client=XXXXXXXXX&token=XXXXXXXX&name=FILE-NAME.png
      5. Copy the link of the request from the browser Network Tab
      6. Try accessing it from a browser where you are not authenticated to Confluence

      Expected Results

      External users who do not have access to the site should not be able to see the image. The link should only be accessible to authorized users

      Actual Results

      External users can download the image with the link shared.

      Workaround

      No workaround available.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              e32c3a85cf21 Uchechi I
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated: