🔒 feat: Authenticated Image Requests #2389
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Implemented authenticated image requests, ensuring secure access to image resources.
This is a bare minimum approach for validation. It is best to use Firebase (hopefully more providers in the future) and manage a CDN policy, but this at least prevents the local images from being "public."
It remains to be seen how this may affect remote environments, as the approach simply relies on browser cookies. A toggle in this case may be necessary.
Also, this may not give the impression that images are secure when they are cached by the browser. Clearing browser cache and trying to access an image outside the app will prove otherwise.
Closes #2385
Changes
Checklist