Bitrix24 Community

Support » Forum » Projects and collaboration » File URLs accessible to non-authenticated users (i.e. anyone)
Pages: 1
RSS
File URLs accessible to non-authenticated users (i.e. anyone)
I added a Word document to my private files area (i.e. not in a shared folder), clicked to view the file, clicked to pop out to a new window, copied the resulting URL ( https://docs.google.com/viewer?url=https://endzonerealty.bitrix24.com/docs/pub/2f26eca1814e01b4b13e47087bf9f21b/TEMPLATE.docx&chrome=true ) into another browser where I wasn't logged in to Bitrix24, and was able to see the document.


Not cool.


Sure, no one will ever guess the URL, but having everyone's files be easily sharable in half a second isn't very secure, especially for HR documents and confidential items.
Hi Cliff!

You don't need to worry. A unique 'secret' is created when you view your documents and it has a lifetime of 15 minutes. No one will be able to access your private documents, even if they get the link somehow.

Regards,

Yana.
Pages: 1
2,000,000+
organizations
are already using Bitrix24