Skip to content

Commit 15c5dae

Browse files
glyemnocon
andcommitted
Added Form Uploads warning (#2551)
* Added Form Uploads warning * Update docs/infrastructure_and_maintenance/security/security_checklist.md Co-authored-by: Marek Nocoń <[email protected]> --------- Co-authored-by: Marek Nocoń <[email protected]>
1 parent ec3df42 commit 15c5dae

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

docs/infrastructure_and_maintenance/security/security_checklist.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -171,6 +171,7 @@ Use the following checklist to ensure the Roles and Policies are secure:
171171
- Is the Role of self-created new users restricted as intended?
172172
- Is there a clear Role separation between the organisation's internal and external users?
173173
- Is access to user data properly restricted, in accordance with GDPR?
174+
- Is access to Form Builder uploads managed properly? Files uploaded with the Form Builder are accessible to any user by default. If this doesn't suit you, restrict access to the Form Uploads folder.
174175

175176
### Do not use "hide" for read access restriction
176177

0 commit comments

Comments
 (0)