• CompactFlax@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    4
    ·
    22 hours ago

    Young.

    The original ticket is 2019. That’s 7 years ago.

    Technically there’s no real problem here.

    It responds to and serves content to unauthenticated requests. That’s sorta table stakes if you’re creating an authenticated web service and providing guides to set it up with a reverse proxy.

    • teawrecks@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      2
      ·
      16 hours ago

      Ok, I misread what you were linking to. Yeah, that’s pretty bad to allow actual streaming of content to unauthed users. I agree they should not be encouraging anyone to set this up to be publicly accessible until those are fixed. Or at least add a warning.