You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Alist can download files without authentication when knowing the file path. Even if the current guest account is closed, even if the target file is outside the basic path of the guest account, you only need to call the download interface http://example.com/d add the path of the file, This may pose a safety hazard.
Please make sure of the following things
alist
and not something else(such asDependencies
orOperational
).Alist Version / Alist 版本
v3.14.0
Driver used / 使用的存储驱动
阿里云盘OPEN
Describe the bug / 问题描述
Alist在知道文件路径的情况下无需认证即可下载文件,即使当前访客账户已关闭,即使目标文件在访客账户基本路径之外,你只需调用下载接口
http://example.com/d
加上文件的路径,这可能存在安全隐患;Alist can download files without authentication when knowing the file path. Even if the current guest account is closed, even if the target file is outside the basic path of the guest account, you only need to call the download interface
http://example.com/d
add the path of the file, This may pose a safety hazard.For example: https://fanscloud.net:5443/d/Adrive/DCIM/Wallpaper/0e3a8fee3823941f6748799025889b3f_3840x2160.jpg
Reproduction / 复现链接
.
Logs / 日志
No response
The text was updated successfully, but these errors were encountered: