Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


    Cloudron Forum

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Solved New Default limited (instead of private)

    HedgeDoc
    3
    6
    248
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • luckow
      luckow translator last edited by

      I know. The Cloudron policy is to use the default upstream settings. But hey. HedgeDoc is a collaboration tool in my understanding. And since no one is able to guess the URL of my "private" notes (others only see the document when you share it with your teammates), we should change the default from private to limited.
      I've spent so many minutes with "Thank you for sharing, but please click limited".

      Limited means: only users can see and edit. No guests (means not public).

      Pronouns: he/him | Primary language: German

      fbartels girish 2 Replies Last reply Reply Quote 2
      • fbartels
        fbartels App Dev @luckow last edited by

        @luckow that's actually a good idea, but may be something that needs to be explicitly mentioned in the app description.

        I just changed the configurable on mine to make notes limited by default.

        luckow 1 Reply Last reply Reply Quote 0
        • luckow
          luckow translator @fbartels last edited by

          @fbartels what concerns do you have about the possible new default? When using HedgeDoc, as expected, there is no potential privacy leak (due to the random url and the missing directory for team member history / new documents).

          Pronouns: he/him | Primary language: German

          fbartels 1 Reply Last reply Reply Quote 0
          • girish
            girish Staff @luckow last edited by girish

            @luckow Double checked this and it seems that the upstream default is actually editable per https://github.com/hedgedoc/hedgedoc/blob/1.8.1/docs/content/configuration.md#users-and-privileges . In the package, we set it to private. I don't think this was a conscious decision.

            I will change the default to editable which is the similar to limited but allows guests to have read only access.

            1 Reply Last reply Reply Quote 1
            • fbartels
              fbartels App Dev @luckow last edited by

              @luckow said in New Default limited (instead of private):

              what concerns do you have about the possible new default?

              I don't really have a concern about it, but when the default changes to something more public it should be highlighted.

              At the very least the urls of notes get logged on the reverse proxy and setting them to editable or limited can mean that the local admin (or someone else with access to logs) could find note urls and view them.

              1 Reply Last reply Reply Quote 1
              • girish
                girish Staff last edited by

                I have updated the package to match upstream default of editable.

                1 Reply Last reply Reply Quote 3
                • First post
                  Last post
                Powered by NodeBB