Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[$500] Public Room-Anonymous user can download images #30806

Closed
3 of 6 tasks
lanitochka17 opened this issue Nov 2, 2023 · 13 comments
Closed
3 of 6 tasks

[$500] Public Room-Anonymous user can download images #30806

lanitochka17 opened this issue Nov 2, 2023 · 13 comments
Assignees
Labels
Bug Something is broken. Auto assigns a BugZero manager. Daily KSv2 External Added to denote the issue can be worked on by a contributor Help Wanted Apply this label when an issue is open to proposals by contributors

Comments

@lanitochka17
Copy link

lanitochka17 commented Nov 2, 2023

If you haven’t already, check out our contributing guidelines for onboarding and email [email protected] to request to join our Slack channel!


**Version Number:**1.3.95-0
**Reproducible in staging?:**Y
**Reproducible in production?:**Y
If this was caught during regression testing, add the test name, ID and link from TestRail:
Email or phone of affected tester (no customers):
Logs: https://stackoverflow.com/c/expensify/questions/4856
Expensify/Expensify Issue URL:
**Issue reported by:**Applause - Internal Team
Slack conversation:

Action Performed:

  1. Log out of New Dot Expensify if previously logged in
  2. Navigate to any public room via url (for example this link - https://staging.new.expensify.com/r/5408450846930023
    )
  3. Verify you can see the announce room as an anonymous user
  4. Right click on any image in the conversation
  5. Click Download

Expected Result:

Clicking on Download should not be allowed to an unauthenticated user, so should be redirected to the Sign In page

Actual Result:

Image is downloaded although anonymous user doesn't have the authentication

Workaround:

Unknown

Platforms:

Which of our officially supported platforms is this issue occurring on?

  • Android: Native
  • Android: mWeb Chrome
  • iOS: Native
  • iOS: mWeb Safari
  • MacOS: Chrome / Safari
  • MacOS: Desktop

Screenshots/Videos

Add any screenshot/video evidence

Bug6261532_1698963588150.anonymous_user_downloads_images.mp4

Bug6261532_1698963588156!anonymous_user_download_images

View all open jobs on GitHub

Upwork Automation - Do Not Edit
  • Upwork Job URL: https://www.upwork.com/jobs/~0114824716246f4944
  • Upwork Job ID: 1720206387814977536
  • Last Price Increase: 2023-11-02
@lanitochka17 lanitochka17 added External Added to denote the issue can be worked on by a contributor Daily KSv2 Bug Something is broken. Auto assigns a BugZero manager. labels Nov 2, 2023
@melvin-bot melvin-bot bot changed the title Public Room-Anonymous user can download images [$500] Public Room-Anonymous user can download images Nov 2, 2023
Copy link

melvin-bot bot commented Nov 2, 2023

Triggered auto assignment to @muttmuure (Bug), see https://stackoverflow.com/c/expensify/questions/14418 for more details.

Copy link

melvin-bot bot commented Nov 2, 2023

Job added to Upwork: https://www.upwork.com/jobs/~0114824716246f4944

@melvin-bot melvin-bot bot added the Help Wanted Apply this label when an issue is open to proposals by contributors label Nov 2, 2023
Copy link

melvin-bot bot commented Nov 2, 2023

Bug0 Triage Checklist (Main S/O)

  • This "bug" occurs on a supported platform (ensure Platforms in OP are ✅)
  • This bug is not a duplicate report (check E/App issues and #expensify-bugs)
    • If it is, comment with a link to the original report, close the issue and add any novel details to the original issue instead
  • This bug is reproducible using the reproduction steps in the OP. S/O
    • If the reproduction steps are clear and you're unable to reproduce the bug, check with the reporter and QA first, then close the issue.
    • If the reproduction steps aren't clear and you determine the correct steps, please update the OP.
  • This issue is filled out as thoroughly and clearly as possible
    • Pay special attention to the title, results, platforms where the bug occurs, and if the bug happens on staging/production.
  • I have reviewed and subscribed to the linked Slack conversation to ensure Slack/Github stay in sync

Copy link

melvin-bot bot commented Nov 2, 2023

Triggered auto assignment to Contributor-plus team member for initial proposal review - @situchan (External)

@tienifr
Copy link
Contributor

tienifr commented Nov 2, 2023

Proposal

Please re-state the problem that we are trying to solve in this issue.

Anonymous user can download images in public rooms.

What is the root cause of that problem?

We allow Download for annonymous user here:

What changes do you think we should make in order to solve the problem?

Set the above prop to false.

What alternative solutions did you explore? (Optional)

NA

@yh-0218
Copy link
Contributor

yh-0218 commented Nov 2, 2023

Proposal

Please re-state the problem that we are trying to solve in this issue.

Anonymous user can download images in public rooms.

What is the root cause of that problem?

Download is allowed for annonymous user.

What changes do you think we should make in order to solve the problem?

  1. we need to update isAnonymousAction: false
  2. we need to add && !Session.isAnonymousUser() here
    shouldShowDownloadButton={props.allowDownload && shouldShowDownloadButton && !isAttachmentReceipt && !isOffline}

What alternative solutions did you explore? (Optional)

Screen.Recording.2023-11-03.at.1.39.16.AM.mov

@DylanDylann
Copy link
Contributor

Proposal

Please re-state the problem that we are trying to solve in this issue.

  • Anonymous user can download images in public rooms.

What is the root cause of that problem?

  • We allow annonymous user to download image.

What changes do you think we should make in order to solve the problem?

  • We have a function fileDownload used to handle download action in entire the app.
    export default function fileDownload(url, fileName) {
  • So we should add the logic check isAnonymousAction to this.

What alternative solutions did you explore? (Optional)

  • NA

@dukenv0307
Copy link
Contributor

It's expected behavior that we decided here #22321

@melvin-bot melvin-bot bot added the Overdue label Nov 6, 2023
Copy link

melvin-bot bot commented Nov 6, 2023

@muttmuure, @situchan Whoops! This issue is 2 days overdue. Let's get this updated quick!

@situchan
Copy link
Contributor

situchan commented Nov 6, 2023

@muttmuure can you please double check the expected behavior?
If this is not bug, I think we should update something since this is reported by QA team.

@melvin-bot melvin-bot bot removed the Overdue label Nov 6, 2023
@NisargDeveloper
Copy link

Are you searching for a resolution?

@melvin-bot melvin-bot bot added the Overdue label Nov 8, 2023
@muttmuure
Copy link
Contributor

Seems like expected behavior to me

@melvin-bot melvin-bot bot removed the Overdue label Nov 9, 2023
@muttmuure
Copy link
Contributor

QA will come back to this issue and see that it is closed as expected. I'm not aware of anywhere that we say it is not.

@lanitochka17 if you find that we say that this should not happen, please let me know where and I will get it updated. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug Something is broken. Auto assigns a BugZero manager. Daily KSv2 External Added to denote the issue can be worked on by a contributor Help Wanted Apply this label when an issue is open to proposals by contributors
Projects
None yet
Development

No branches or pull requests

8 participants