Images should not be served by django #9

Open
opened 2022-07-05 21:58:49 +01:00 by max · 0 comments
Owner

Images should also not just be served as part of the media files. That would allow people to sidestep auth.

I think nginx supports X-Send-File or something like that, that would allow django to instruct it to send a particular file that is otherwise not served directly (it's outside of the document root).

Images should also not just be served as part of the media files. That would allow people to sidestep auth. I think nginx supports X-Send-File or something like that, that would allow django to instruct it to send a particular file that is otherwise not served directly (it's outside of the document root).
max added the
enhancement
label 2022-07-05 21:58:49 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: max/flangr#9
No description provided.