Skip to content

Commit 7f22a70

Browse files
glyemnocon
andauthored
Added Form Uploads warning (#2551)
* Added Form Uploads warning * Update docs/infrastructure_and_maintenance/security/security_checklist.md Co-authored-by: Marek Nocoń <[email protected]> --------- Co-authored-by: Marek Nocoń <[email protected]>
1 parent e68a80c commit 7f22a70

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

docs/infrastructure_and_maintenance/security/security_checklist.md

+1
Original file line numberDiff line numberDiff line change
@@ -171,6 +171,7 @@ Use the following checklist to ensure the Roles and Policies are secure:
171171
- Is the Role of self-created new users restricted as intended?
172172
- Is there a clear Role separation between the organisation's internal and external users?
173173
- Is access to user data properly restricted, in accordance with GDPR?
174+
- Is access to Form Builder uploads managed properly? Files uploaded with the Form Builder are accessible to any user by default. If this doesn't suit you, restrict access to the Form Uploads folder.
174175

175176
### Do not use "hide" for read access restriction
176177

0 commit comments

Comments
 (0)