Skip to content

Conversation

@rosa
Copy link
Member

@rosa rosa commented Dec 25, 2025

Consider blobs attached to any public records accessible to anyone with the URL.

rosa added 2 commits December 25, 2025 21:22
Consider blobs attached to any public records accessible to anyone with
the URL.
Avatars are purposely accessible without authentication
(5e3b5b6) because they can be in public
collections. Trying to restrict this by checking whether they're in fact
present in some public collection is rather expensive, so let's keep
them public.
@rosa rosa merged commit 55257c8 into main Dec 29, 2025
12 checks passed
@rosa rosa deleted the active-storage-authorization branch December 29, 2025 11:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants