WWBN / AVideo

Create Your Own Broadcast Network With AVideo Platform Open-Source. OAVP OVP
https://avideo.tube/AVideo_OpenSource
Other
1.9k stars 971 forks source link

Security risk #8958

Open para2022 opened 6 months ago

para2022 commented 6 months ago

In the video panel where all the videos are located.

Where it shows what storage is being used on each video. If you click on it, it is a live link taking users to the location of where the videos are stored. That is a recipe for disaster for potential hacking of the videos to the platform. Users do not need to be taken there and they should not have any need to know where the videos are stored. That should be absolutely private for security reasons. Not even the admin needs a live link there as they know where the storage location is. The live link needs removing.

DanielnetoDotCom commented 6 months ago

what exactly do you mean, can you please screenshot?

can you show me a sample on the demo site?

para2022 commented 6 months ago

Screenshot 2024-04-06 at 19 32 22

Where 'storage 1' is in purple. That is a live link that can take users to the storage login page. Not needed mate. If someone ever breached that they could delete all videos to a platform.

DanielnetoDotCom commented 6 months ago

Sorry, I totally disagree, this is not a Security risk

If he knows the admin password to login in to the storage, you are already dead.

para2022 commented 6 months ago

Sorry, I totally disagree, this is not a Security risk

If he knows the admin password to login in to the storage, you are already dead.

Why is it needed in the first place? The admin knows exactly where the storage is as he put it there. Users should have no business knowing where storage locations are anyway. They are just users of the site and shouldnt be knowing such things. It really isnt for them to know.

walt93 commented 6 months ago

Becuase this is a shortcut to getting a live CDN url for the video, which is used for certain work flows. This is an admin function & as Daniel said, if they have the root password - you've got many other issues to be concerned with.