[BUG] Privacy issue: photos page viewable without login #188

Closed
opened 2026-02-04 18:35:31 +03:00 by OVERLORD · 0 comments
Owner

Originally created by @lianqiw on GitHub (Aug 8, 2022).

Describe the bug
If I point my browser from a Incognito browser window or from a different machine to the immich server http://ip:2883/photos without login, the structure of the photos are viewable, including the dates, the logged in user, except that the actual photos do not load.

Task List

Please complete the task list below. We need this information to help us reproduce the bug or point out problems in your setup. You are not providing enough info may delay our effort to help you.

  • I have read thoroughly the README setup and installation instructions.
  • I have included my docker-compose file.
  • I have included my redacted .env file.
  • I have included information on my machine, and environment.

To Reproduce
Steps to reproduce the behavior:

  1. Go to a browser that have not logged in to the immich_server
  2. visit 'http://immich_server/photos'
  3. Do not log in
  4. See that the page loads with only photos hidden

Expected behavior
Should not show anything and redirect user to login page

Screenshots
image

System

  • Phone OS [iOS, Android]: iOS
  • Server Version: 1.20.0
  • Mobile App Version: 1.20.0

Additional context
Add any other context about the problem here.

Originally created by @lianqiw on GitHub (Aug 8, 2022). **Describe the bug** If I point my browser from a Incognito browser window or from a different machine to the immich server http://ip:2883/photos without login, the structure of the photos are viewable, including the dates, the logged in user, except that the actual photos do not load. **Task List** *Please complete the task list below. We need this information to help us reproduce the bug or point out problems in your setup. You are not providing enough info may delay our effort to help you.* - [X] I have read thoroughly the README setup and installation instructions. - [ ] I have included my `docker-compose` file. - [ ] I have included my redacted `.env` file. - [X] I have included information on my machine, and environment. **To Reproduce** Steps to reproduce the behavior: 1. Go to a browser that have not logged in to the immich_server 2. visit 'http://immich_server/photos' 3. Do not log in 4. See that the page loads with only photos hidden **Expected behavior** Should not show anything and redirect user to login page **Screenshots** <img width="1389" alt="image" src="https://user-images.githubusercontent.com/158336/183313496-23c71dd6-d499-438d-8f7f-55c0b7cb1197.png"> **System** - Phone OS [iOS, Android]: `iOS` - Server Version: `1.20.0` - Mobile App Version: `1.20.0` **Additional context** Add any other context about the problem here.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: immich-app/immich#188