advanced-nova-media-library icon indicating copy to clipboard operation
advanced-nova-media-library copied to clipboard

Accessing media and Policies

Open stardothosting opened this issue 3 years ago • 0 comments

I have a policy as well as a resource index filter to control which user can see what resource item.

Because I want to control who can view a specific item within a Nova resource, I notice that there is no clear way to ensure that a user cannot just type any random download link ID to obtain access to the respective file.

For example, is it possible to include authorization / policy checks when a direct file access attempt is made such as :

http://site.local/nova-vendor/ebess/advanced-nova-media-library/download/6

It seems that any user can access any file this way.

stardothosting avatar Jun 08 '21 12:06 stardothosting