There was an image in the storage bucket that was pushed to production as a link like this https://ENDPOINT_URL/v1/storage/buckets/BUCKET_ID/files/FILE_ID/view?project=PROJECT_ID does it mean that project was compromised and in theory anybody can access to it with sdk?
Hi 👋 View, preview and download endpoints for files all respect permissions. You can open Appwrite Console and check settings of your bucket. Whoever has read permissions was possibly allowed to see the file.
If you have file security enabled, also please view details of a file in Appwrite Console and check permissions there. Those with read permissions on file could aslo possibly read the file
Recommended threads
- It says domain already used but I have d...
I accidentally deleted the project in which I used my domain originally (orexia.app) from name.com. Now I am trying to add it to a different project and it says...
- Is this normal in the self host custom d...
when i try to add custom domain to the project did not see this in 1.8.0 ok when pressed the retry it says "DNS verification failed with resolver 8.8.8.8. Domai...
- No server error on selfhosted appwrite
Please help me, my clients is ask what happen on their data? How can i make it up again?