Jump to content

Disable "Download to" function


Recommended Posts

Guest Skynet.v01
Posted
Hello

I had already talked about it, but it would be nice to be able to disable the "download to" function while keeping the "download" function.

Because any user can send downloads to other users' devices.

Or, users would only see their own devices, not those connected to other accounts.
 
darkassassin07
Posted (edited)

I hadn't even thought about that, but testing it now: users that have the ability to download media can queue that media for download on any unique device even if they have never signed into it.

(my test guest account can download media to my admin accounts android phone as well as every other users devices)

Definitely a +1 to this request

Edited by darkassassin07
Posted

This is based on the devices they are granted access to.

Guest Skynet.v01
Posted

But a device that has a guest account configured (and no other) can send a download to another user's device without having that other user's account or admin rights.
That is problematic, it's as if a Netflix subscriber could send a download to the device of any other subscriber in the world.

 

I insist but it would be very useful to:

- prevent downloading to another device (for example a checkbox in the user profiles to disable the "download to" function)
- or don't display for each user the devices of all users, only those connected with his account

Posted

Yes it's something that can continue to be improved. Thanks for the feedback .

darkassassin07
Posted

This could be tied into the remote control settings in a users profile settings.

'Allow remote control of other users'

'Allow remote control of shared devices'

And 'Allow media downloading'

Would all be required to use the 'download to' function.

That or a seprate 'Allow media downloading to remote devices' checkbox.

 

As a server admin I don't really want my users to be able to send downloads to other users devices at all, given the option I'd disable that server wide.

  • 2 months later...
SuperMinecraftKid
Posted

+1 

  • 10 months later...
CyberPoison
Posted
On 11/28/2019 at 8:27 PM, Luke said:

Yes it's something that can continue to be improved. Thanks for the feedback .

This is not really an improvement is a security concern .

But i hope it will be able to disable download to or allow only download to option to the user device it uses

CyberPoison
Posted (edited)
On 11/28/2019 at 7:23 AM, Skynet.v01 said:
Hello

I had already talked about it, but it would be nice to be able to disable the "download to" function while keeping the "download" function.

Because any user can send downloads to other users' devices.

Or, users would only see their own devices, not those connected to other accounts.
 

Edit your post/thread topic to ( [Security Risk] Download to cause security risk )and add that tag Security Risk 

Edited by CyberPoison
CyberPoison
Posted (edited)

unknown.png?width=525&height=684

Things like this need to be mitigate and treated as well because of the security risk of the Emby Users 

 

Options like this should exist.

Disable Download to...
Allow Download to (Only User Device) 

Edited by CyberPoison
Posted
2 hours ago, CyberPoison said:

allow only download to option to the user device it uses

You can do that by restricting the user profile to the devices they use.

If you do that, then they will only be allowed to download to the allowed devices.

seanbuff
Posted
2 hours ago, neik said:

You can do that by restricting the user profile to the devices they use.

The problem with that is, users won't be able to use any new devices (new phone, iPad) until they try, it fails, then they contact you with the problem and you enable it. Not ideal.

Posted
21 minutes ago, seanbuff said:

The problem with that is, users won't be able to use any new devices (new phone, iPad) until they try, it fails, then they contact you with the problem and you enable it.

Correct. But still, it does the job.

  • 2 weeks later...
Posted

Hi, this will be revamped in Emby Server 4.6. It will follow the user's remote control permissions. If they don't have permission to control other user's devices, then they won't be able to download to them either. Thanks for the feedback.

Guest
This topic is now closed to further replies.
×
×
  • Create New...