Anyone signed in can read any feed's items and files, a private feed's included #129

Closed
opened 2026-10-05 09:10:09 -07:00 by rays · 1 comment
Owner

Routes that take a feed or enclosure id do not check that the person asking subscribes to it:

  • GET /api/feeds/{id}/entries returns any feed's items with their enclosures, enclosure URLs included. A paid feed's enclosure URLs can carry the subscriber's key, and its items are what they pay for: the Directory leaves such feeds out (looks_private) for exactly that reason, and this route gives them back to anyone who guesses the id, a slug of the title.
  • GET /media/{id} serves any downloaded file by its sequential id.
  • POST /api/enclosures/{id}/download queues any enclosure for download.
  • DELETE /api/enclosures/{id} deletes any file; ?force=true skips the warning.

Found 2026-10-05 while adding a preview of Directory feeds (#128): /api/feeds/human-nature-blog-feed/entries answered 25 items to an account that does not subscribe to it. Every account here is someone the admin let in, which limits who could, but not what they could see.

Routes that take a feed or enclosure id do not check that the person asking subscribes to it: - GET /api/feeds/{id}/entries returns any feed's items with their enclosures, enclosure URLs included. A paid feed's enclosure URLs can carry the subscriber's key, and its items are what they pay for: the Directory leaves such feeds out (looks_private) for exactly that reason, and this route gives them back to anyone who guesses the id, a slug of the title. - GET /media/{id} serves any downloaded file by its sequential id. - POST /api/enclosures/{id}/download queues any enclosure for download. - DELETE /api/enclosures/{id} deletes any file; ?force=true skips the warning. Found 2026-10-05 while adding a preview of Directory feeds (#128): /api/feeds/human-nature-blog-feed/entries answered 25 items to an account that does not subscribe to it. Every account here is someone the admin let in, which limits who could, but not what they could see.
Author
Owner

Fixed in b86062b: entries, download-latest, /api/enclosures/{id} (download and delete) and /media/{id} answer 404 unless you subscribe to the feed. Deployed 2026-10-05: /api/feeds/human-nature-blog-feed/entries now answers 404 to an account that does not subscribe to it, while that account's own feeds, those inside an OPML included, and its files still answer. Flags and position on someone else's feed still write the asker's own state only, which leaks nothing, and are left alone.

Fixed in b86062b: entries, download-latest, /api/enclosures/{id} (download and delete) and /media/{id} answer 404 unless you subscribe to the feed. Deployed 2026-10-05: /api/feeds/human-nature-blog-feed/entries now answers 404 to an account that does not subscribe to it, while that account's own feeds, those inside an OPML included, and its files still answer. Flags and position on someone else's feed still write the asker's own state only, which leaks nothing, and are left alone.
rays closed this issue 2026-10-05 09:21:25 -07:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: rays/ipx#129