Skip to content

Conversation

@rosa
Copy link
Member

@rosa rosa commented Dec 25, 2025

Consider blobs attached to any public records accessible to anyone with the URL.

rosa added 2 commits December 25, 2025 21:22
Consider blobs attached to any public records accessible to anyone with
the URL.
Avatars are purposely accessible without authentication
(5e3b5b6) because they can be in public
collections. Trying to restrict this by checking whether they're in fact
present in some public collection is rather expensive, so let's keep
them public.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants