Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable direct link due to security concerns #1131

Open
funkyapple opened this issue Dec 29, 2023 · 1 comment
Open

Disable direct link due to security concerns #1131

funkyapple opened this issue Dec 29, 2023 · 1 comment

Comments

@funkyapple
Copy link

funkyapple commented Dec 29, 2023

Hi,

So just a couple thoughts. I was wondering if tinyfilemanager supports disabling the direct link feature entirely? I don't rlly understand how the program works so not sure how feasible that would be.

My main concern would be that some of my config files contain sensitive information. It appears the direct links can be accessed without user authentication which would be a problem if any configs contained unencrypted passwords (yes I know, bad practice but in dev server sometimes easier). I really love however the rich text editor of tinyfilemanager so it would be neat if this was possible. It really is a god send when it comes to editing yaml files (which is what I often do all day).

One idea I had would be to secure tinyfilemanager behind something like Authelia just would take some time to config.

@hestiacn
Copy link

hestiacn commented May 4, 2024

You can create an offline version for your own intranet use. No need to worry about data leakage

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant