mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-02-05 16:49:47 +03:00
Improve documentation/add-clarification around the storage options and thier permission enforcement, including notice on roles view #3050
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @brynmoorhouse on GitHub (Aug 30, 2022).
Attempted Debugging
Searched GitHub Issues
Describe the Scenario
This is possibly me misunderstanding the feature, or it might be a bug, but I've enabled the following in my .env
STORAGE_TYPE=local_secureI've verified that all images are being uploaded to storage/uploads (outside the public directory), but yet I can still enter the direct image URL in an incognito tab to view the image. I'd expect that I'd need to be logged in to view the image?
I did find issue #2998, which is the same scenario, apart from I have not set STORAGE_IMAGE_TYPE at all, which if I've read the docs correctly, means that it will use STORAGE_TYPE
Thanks,
Exact BookStack Version
v22.07.3
Log Content
No response
PHP Version
8.1
Hosting Environment
Debian 10, NGINx, PHP 8.1 fpm