Hello,
I would like to share a very strange behaviour, I have an account on trello with my company and we upload some attachement to the diferents tickets. But recently I noticed that we can have an access to the attachment even if we don't have an account on trello ! It's open bar !
Why ? It's a security problem...
PS: Url begin with: https://trello-attachments.s3.amazonaws.com/.....
@Itafr italiano firstly, yes that's true but you'll notice that the link is very obscure, it's kind of like when you set a Google Doc such that anyone with the link can view. If someone gets the link, they can see it without being logged in, but guessing the link is mathematically impossible.
However, Trello is changing this behaviour:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.