diff options
author | Louise Crow <louise.crow@gmail.com> | 2012-12-13 12:16:46 +0000 |
---|---|---|
committer | Louise Crow <louise.crow@gmail.com> | 2012-12-13 12:50:50 +0000 |
commit | 3910f7f545177cdb69a5ee0196ffa54a9dba0541 (patch) | |
tree | 2da09ec794193e1b08644902aa1276dbad33a8dc /app/controllers/api_controller.rb | |
parent | 2078f60edf819cae81b5f15bedf93db9bae4df53 (diff) |
Don't offer or allow viewing of an HTML version of a response attachment if the request is hidden, or requester_only. Google docs viewer won't be able to access it, and our own conversion process currently can produce image files that will then be publicly viewable directly from the webserver (see config/httpd.conf). If necessary we can revisit this code to enable admins and requesters to view the HTML version created by our own conversion without adding these files to a path that is served directly by the web server.
Diffstat (limited to 'app/controllers/api_controller.rb')
0 files changed, 0 insertions, 0 deletions