-
越权访问如题,在无痕模式下,未登录任何账号。 如果有恶意脚本扫描文件路径,则有极大可能泄露AList挂载的私人文件内容。 禁用访客用户在禁用访客用户后,依旧可通过链接直接下载文件内容,无需鉴权,存在极大安全隐患。 安全隐患因AList链接基本是按文件路径构造,很容易进行伪造。 |
Beta Was this translation helpful? Give feedback.
Answered by
Doradx
Dec 7, 2023
Replies: 1 comment
-
已找到解决方案,给全站直链添加签名。 |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
Doradx
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
已找到解决方案,给全站直链添加签名。
https://alist.nn.ci/zh/config/global.html#%E7%AD%BE%E5%90%8D%E6%89%80%E6%9C%89