HOW TO DISABLE ANONYMIZEFILENAME? #724

Closed
opened 2024-03-29 07:16:26 +00:00 by lamp · 5 comments

0b2ec0ccee

"The AnonymizeFilename filter is now enabled by default."

WHY?

It make "Link name" function USELESS. image image

How to disable??

https://akkoma.dev/AkkomaGang/akkoma/commit/0b2ec0cceea4774bd652ab3cf353cfc928c2990e "The AnonymizeFilename filter is now enabled by default." WHY? It make "Link name" function USELESS. ![image](/attachments/50fbc0d1-c20e-491c-a288-1b32250a060f) ![image](/attachments/2e1658f8-4936-4fd6-97b1-184509d96a8d) How to disable??

fair point about this toggle, we should remove the link name thing - it's a relic of the old system

as for why it's enabled by default, predictable filenames can be used by bad actors and pose a security risk

fair point about this toggle, we should remove the link name thing - it's a relic of the old system as for why it's enabled by default, predictable filenames can be used by bad actors and pose a security risk
Author

"enabled by default" implies there's a way to disable it, but it appears it's just "enabled" permanently.

"enabled by default" implies there's a way to disable it, but it appears it's just "enabled" permanently.

this is correct

this is correct
Author

well especially considering you can upload files other than media it would be nice to keep the file name with it somehow. whats the security risk, are you talking about risk of arbitrary filenames like /media/index.html, risk of finding posts by file name or risk of confidential info in file names?

well especially considering you can upload files other than media it would be nice to keep the file name with it somehow. whats the security risk, are you talking about risk of arbitrary filenames like /media/index.html, risk of finding posts by file name or risk of confidential info in file names?

with the security patch it was made optional as the thing it was covering was fixed at the source

with the security patch it was made optional as the thing it was covering was fixed at the source
Sign in to join this conversation.
No Milestone
No project
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: AkkomaGang/akkoma#724
No description provided.