Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. HedgeDoc
  3. New Default limited (instead of private)

New Default limited (instead of private)

Scheduled Pinned Locked Moved Solved HedgeDoc
6 Posts 3 Posters 1.1k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • luckowL Offline
      luckowL Offline
      luckow
      translator
      wrote on last edited by
      #1

      I know. The Cloudron policy is to use the default upstream settings. But hey. HedgeDoc is a collaboration tool in my understanding. And since no one is able to guess the URL of my "private" notes (others only see the document when you share it with your teammates), we should change the default from private to limited.
      I've spent so many minutes with "Thank you for sharing, but please click limited".

      Limited means: only users can see and edit. No guests (means not public).

      Pronouns: he/him | Primary language: German

      fbartelsF girishG 2 Replies Last reply
      2
      • luckowL luckow

        I know. The Cloudron policy is to use the default upstream settings. But hey. HedgeDoc is a collaboration tool in my understanding. And since no one is able to guess the URL of my "private" notes (others only see the document when you share it with your teammates), we should change the default from private to limited.
        I've spent so many minutes with "Thank you for sharing, but please click limited".

        Limited means: only users can see and edit. No guests (means not public).

        fbartelsF Offline
        fbartelsF Offline
        fbartels
        App Dev
        wrote on last edited by
        #2

        @luckow that's actually a good idea, but may be something that needs to be explicitly mentioned in the app description.

        I just changed the configurable on mine to make notes limited by default.

        luckowL 1 Reply Last reply
        0
        • fbartelsF fbartels

          @luckow that's actually a good idea, but may be something that needs to be explicitly mentioned in the app description.

          I just changed the configurable on mine to make notes limited by default.

          luckowL Offline
          luckowL Offline
          luckow
          translator
          wrote on last edited by
          #3

          @fbartels what concerns do you have about the possible new default? When using HedgeDoc, as expected, there is no potential privacy leak (due to the random url and the missing directory for team member history / new documents).

          Pronouns: he/him | Primary language: German

          fbartelsF 1 Reply Last reply
          0
          • luckowL luckow

            I know. The Cloudron policy is to use the default upstream settings. But hey. HedgeDoc is a collaboration tool in my understanding. And since no one is able to guess the URL of my "private" notes (others only see the document when you share it with your teammates), we should change the default from private to limited.
            I've spent so many minutes with "Thank you for sharing, but please click limited".

            Limited means: only users can see and edit. No guests (means not public).

            girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by girish
            #4

            @luckow Double checked this and it seems that the upstream default is actually editable per https://github.com/hedgedoc/hedgedoc/blob/1.8.1/docs/content/configuration.md#users-and-privileges . In the package, we set it to private. I don't think this was a conscious decision.

            I will change the default to editable which is the similar to limited but allows guests to have read only access.

            1 Reply Last reply
            1
            • luckowL luckow

              @fbartels what concerns do you have about the possible new default? When using HedgeDoc, as expected, there is no potential privacy leak (due to the random url and the missing directory for team member history / new documents).

              fbartelsF Offline
              fbartelsF Offline
              fbartels
              App Dev
              wrote on last edited by
              #5

              @luckow said in New Default limited (instead of private):

              what concerns do you have about the possible new default?

              I don't really have a concern about it, but when the default changes to something more public it should be highlighted.

              At the very least the urls of notes get logged on the reverse proxy and setting them to editable or limited can mean that the local admin (or someone else with access to logs) could find note urls and view them.

              1 Reply Last reply
              1
              • girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #6

                I have updated the package to match upstream default of editable.

                1 Reply Last reply
                3
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • Bookmarks
                  • Search