A file's edit form shows the person their storage path, account id and all #191
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#191
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Found while fixing #167, which was about the same line for a different reason.
/documents/files/<pk>/edit/renders, from Django'sClearableFileInput:The person uploaded a file called
reference.txt. What they are shown isdocuments/1/2026/09/reference.txt— the path it is stored at, which carries their accountid and the month they uploaded it, neither of which they asked about and neither of
which is theirs to care about.
Why it is worth fixing beyond tidiness
answer is
reference.txt. The rest is Postulo's filing system thinking aloud.people have seen and might rely on. A future change to
upload_tothen looks like a changeto them rather than to storage.
UploadedDocument.titlealready answers. The form has a Titlefield immediately above showing "Reference". The path adds nothing and contradicts it in
tone.
What it is not
Not a serious disclosure. The path is the person's own, behind their own login, and
/media/is already how they download it. This is an interface fault with a small privacyedge — a screen shared in a call now shows an account id — rather than a leak to anybody
else.
Doing it
Django builds that string from the widget's value, whose
__str__is the stored name. Thenarrow fix is a widget that renders the basename, applied wherever a file field is shown;
partials/field.htmlis where every field already passes through, so that is the naturalplace for it to take effect without each form remembering.
Worth checking at the same time: the same widget is used by any other file field — the
Europass import and the plugin upload on the server pages — so the fix should be one widget
rather than one template.
#167 already stopped it running off a phone, by letting the field container wrap
anywhere. That is a fix for the symptom and stands on its own: whatever string ends up there,
it should not scroll the page sideways.
Reproduced, and narrower than this issue claimed
Rendered the page against a fresh upload, with a space in the filename to see the
sanitising as well:
So it is exactly as described: the person uploaded
my cv.pdfand is showndocuments/1/2026/09/my_cv.pdf— their account id, the month, and a name Django rewrote.Correcting this issue: it is one form, not several
The body says to check "the Europass import and the plugin upload" and to fix one widget
rather than one template. Having looked, only one form exposes a bound model file field:
Everything else that takes a file does it differently and never renders
Currently::accounts/forms.pyuses a plainforms.FileFieldfor the profile picture — unbound, soDjango has no stored value to print.
Company.logois set programmatically and is on no form.the same form then re-renders.
Currently:only appears for a ModelForm field bound to an instance that already has afile, and
UploadedDocumentFormon the edit page is the only one of those. That makes thefix smaller than written — though a widget rather than a template is still the better shape,
because the next ModelForm file field should not have to remember.
Still worth doing, and still only cosmetic-with-an-edge
Nothing here is exposed to anybody else: the path is the person's own, behind their own
login, and
/media/is already how they fetch it. The fault is that the field answerswhich file is this? with Postulo's filing system instead of the filename, on a page whose
Title field two rows above already says "Reference".
d4b8bf3d6(#167) stopped it scrolling the page sideways by letting the container wrapanywhere. That stands on its own whatever string ends up there.