Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Change AWS_DEFAULT_ACL to None #17

Closed
vkurup opened this issue Jan 20, 2021 · 0 comments · Fixed by #21
Closed

Change AWS_DEFAULT_ACL to None #17

vkurup opened this issue Jan 20, 2021 · 0 comments · Fixed by #21

Comments

@vkurup
Copy link
Contributor

vkurup commented Jan 20, 2021

AWS_DEFAULT_ACL is currently set to public-read which allows user-uploaded media to be publically accessible. This might be OK for some sites, but I think it's a better default to set it to None so that it inherits the permissions of the bucket that it is in.

Some background: jschneier/django-storages#535

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant