Skip to content

Cached remote meda filenames might collide #2742

@Menrath

Description

@Menrath

Currently the attachments class is using just the files basename for cached attachments.

This has problems:

  • Attachments of the same post might have the same basename and therefore collissions might occur.
  • The basename might be guessed and therefore private images might get easily guessed.

I propose a more nuanced way of caching remote media: Use the original URL to generate a hash for the filename.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions