Comment 20 for bug 1756904

Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

We would need to rethink the approach, e.g. use an ID instead of the folder or file title. But it shouldn't be a number ID that can be enumerated but it would be better to use a random sequence of letters, numbers, and some special characters to make guessing the ID more difficult (see how social media sites do that). That would enhance the security as URLs can't be guessed. While that is not so important for a download because that lives locally, it is important for the online viewing.