Skip to content

Commit 74a4f36

Browse files
glyemnocon
andcommitted
Added Form Uploads warning (#2551)
* Added Form Uploads warning * Update docs/infrastructure_and_maintenance/security/security_checklist.md Co-authored-by: Marek Nocoń <[email protected]> --------- Co-authored-by: Marek Nocoń <[email protected]>
1 parent 9ab9895 commit 74a4f36

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

docs/guide/security_checklist.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -165,6 +165,7 @@ Use the following checklist to ensure the Roles and Policies are secure:
165165
- Is the Role of self-created new users restricted as intended?
166166
- Is there a clear Role separation between the organisation's internal and external users?
167167
- Is access to user data properly restricted, in accordance with GDPR?
168+
- Is access to Form Builder uploads managed properly? Files uploaded with the Form Builder are accessible to any user by default. If this doesn't suit you, restrict access to the Form Uploads folder.
168169

169170
### Do not use "hide" for read access restriction
170171

0 commit comments

Comments
 (0)