• GitHub
  • Documentation
  • Discord
  • Donate
search
  • chevron_right Threads
  • label Feedback

private message attachments are not private

ufukayyildiz
April 19, 2025
chat_bubble_outline 2
  • link
    ufukayyildiz
    Members 9 posts
    April 19, 2025, 4:46 a.m. April 19, 2025, 4:46 a.m.
    link

    Hi,

    private message attachments are not private they shown if someone has url.

    Are they indexable?

  • link
    rafalp
    Project Lead 1976 posts
    April 19, 2025, 12:06 p.m. April 19, 2025, 12:06 p.m.
    link

    This is by design.

    If I have link to the attachment in the first place, whats to stop me from downloading the file and sharing it with others anyway?

    Bots wont find attachment unless link to it is posted somewhere.

    In 0.40 there is extra permission check fir accessing attachment, but as I’ve said, the feeling of security of attachments on internet forums is a false feeling, so use third party file sharing like google drive for security sensitive files like confidential PDF documents.

    ufukayyildiz likes this.

    favorite 1

  • link
    rafalp
    Project Lead 1976 posts
    April 19, 2025, 12:08 p.m. April 19, 2025, 12:08 p.m.
    link

    Removing this from bugs. If you search this for other forum software, you will get same reply - use forum attachments for memes, pics, or game mods, never for confidential PDFs.

arrow_upward Go to top
  • This site uses cookies to gather statistical data for use in traffic analysis.
  • GitHub
  • Documentation
  • Discord
  • Donate
  • Terms of service
  • Privacy policy
powered by misago