How to prevent anonymous access to private files in group nodes?

Created on 10 June 2025, 5 days ago

Problem/Motivation

Private files uploaded to the site's private directory in a group node are visible to anonymous site visitors even though the node itself is protected. Is there a solution to this issue? I looked at the old issues and didn't see any solution to this.

Steps to reproduce

  1. Create a new group node.
  2. Embed a file in the node body using private file upload.
  3. Save the node.
  4. Click on the file item to open it.
  5. Copy the URL.
  6. Open a private browser window (not logged in) and paste the URL.
  7. The private file is displayed.

Proposed resolution

Information on how to secure the private files from being viewed by anonymous visitors.

Remaining tasks

User interface changes

API changes

Data model changes

💬 Support request
Status

Active

Version

2.3

Component

Code

Created by

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024