Jump to content

Bug in "content rights" under "Direct Link". Authorization by LDAP


Recommended Posts

Posted (edited)

Good afternoon.
I wanted to draw your attention to the following question...
We use LDAP Authorization (via Plugin) and regulate access for each client at the level of Medialibrary and Sub-folders.
And it works great!

By default - each User who is an Authorizer on LDAP method gets an Empt set of rights on All MediaLibrary. (hereinafter, according to his Rights Template, he is given a set of Folders he needs).
image.png.837ecbce5b80b48b3692d0723f228f21.png
image.png.d14d39fb44c053cf38974068ca64fb12.png
At the same time, each content (videos or movie) has a "unique" link.
image.thumb.png.aa22c190aa7625fea15dbcb8f037a994.png
We noticed that a number of users began to share these links among themselves.
And these users (from other departments of the company) should not have access to them.
However, such "Direct Links" are not protected by EMBY in any way.

We think it's a BUG! We would like you to consider this as it is a potential account through which users can access content bypassing "permissions".

Thank you!
 

Edited by Santrex
Happy2Play
Posted (edited)

Don't know anything about the LDAP plugin, Devs will have to comment, but yes knowing the url/itemid can circumvent access restrictions on an authenticated user in my tests. @Luke

tested current release and beta (if itemid is known any item can be accessed)

 

Edited by Happy2Play
  • Agree 1
Posted
On 2/14/2023 at 2:00 AM, Happy2Play said:

Don't know anything about the LDAP plugin, Devs will have to comment, but yes knowing the url/itemid can circumvent access restrictions on an authenticated user in my tests. @Luke

tested current release and beta (if itemid is known any item can be accessed)

 

Yes, that's right. The problem is exactly this.
Can you do it? Perhaps some kind of "key" in order to be able to switch these access check modes.

Posted

HI, we'll take a look at it. Thanks for reporting.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...