Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

[BUG] Attachment access without login

Itafr italiano
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 7, 2020

Hello,

I would like to share a very strange behaviour, I have an account on trello with my company and we upload some attachement to the diferents tickets. But recently I noticed that we can have an access to the attachment even if we don't have an account on trello ! It's open bar !

Why ? It's a security problem...

PS: Url begin with: https://trello-attachments.s3.amazonaws.com/.....

1 answer

0 votes
Iain Dooley
Community Champion
September 7, 2020

@Itafr italiano firstly, yes that's true but you'll notice that the link is very obscure, it's kind of like when you set a Google Doc such that anyone with the link can view. If someone gets the link, they can see it without being logged in, but guessing the link is mathematically impossible.

However, Trello is changing this behaviour:

https://community.developer.atlassian.com/t/authenticated-access-to-s3/40647?_ga=2.131524687.1164060461.1598221099-299049771.1576052240

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events