You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For security, I have the option 'allow_access_to_all_files' switched to 'false'.
However, I discovered that when clicking on 'file details', the getid3-plugin offers a browse possibility via which the entire file system is visible. It is only viewable, but even this already seems to me an unwanted security hole. Is there a solution, apart from deleting the entire plugin?
Steps to reproduce: for a random music file in O!MPD, click on 'file details'. Top line on screen shows 'Browse'. From there, it is possible to navigate through the entire directory tree (as far as rights permit, of course)
The text was updated successfully, but these errors were encountered:
For security, I have the option 'allow_access_to_all_files' switched to 'false'.
However, I discovered that when clicking on 'file details', the getid3-plugin offers a browse possibility via which the entire file system is visible. It is only viewable, but even this already seems to me an unwanted security hole. Is there a solution, apart from deleting the entire plugin?
Steps to reproduce: for a random music file in O!MPD, click on 'file details'. Top line on screen shows 'Browse'. From there, it is possible to navigate through the entire directory tree (as far as rights permit, of course)
The text was updated successfully, but these errors were encountered: