cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Learn all about how Alex on the Community team used Dropbox in college here!

Dropbox files & folders

Get in sync with the Dropbox Community. Our members can answer all your questions on Dropbox files and folders. Join a discussion or start your own today.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

URL of non-shared document gives access to file content

URL of non-shared document gives access to file content

314159
Explorer | Level 3
 

I am very surprised that I linked on a Dropbox URL stored in my web browser's history and, without being logged in, I could see the content of the file.

 

I have created a new file to test it and, just with the URL that is accessed by the web browser, anyone can see this file which theoretically has never been shared with anyone: https://www.dropbox.com/scl/fi/eprarh4pibp39mrrgsqw6/Document.docx?dl=0&new=1&rlkey=ghlowj8k67bf5vlj...

 

I know that you will say that the URL is "secret", but URLs can be seen:

  • By other users even if I have logged out from Dropbox.
  • The ISP.
  • Anyone who guesses a URL (probably this is impossible in practice).

Do you know if this is normal? Isn't it a big security concern?

3 Replies 3

Re: URL of non-shared document gives access to file content

Rich
Super User II

@314159 wrote:

I have created a new file to test it and, just with the URL that is accessed by the web browser, anyone can see this file which theoretically has never been shared with anyone


That file appears to be shared via a share link, and anyone with the link would be able to access it. If you don't generate a link to the file, it won't be accessible.

Re: URL of non-shared document gives access to file content

314159
Explorer | Level 3

If that was the case I would think that the working of Dropbox is normal and not concerning but it's not. I am pretty sure that I just created a new document in my main Dropbox folder on dropbox.com and I didn't create a share link, I just copied the URL my web browser showed when creating the new document.

 

I can show that I have no shared files or links at this moment (only three links created some time ago to other files) but yesterday's link still works:

1.PNG2.PNG

If this is not how Dropbox should work, is it some bad configuration I have or is it a bug I am suffering? Because it's clear, and more after reading to a Super User, that it shouldn't be the normal functioning.

Re: URL of non-shared document gives access to file content

314159
Explorer | Level 3

Can it have any relation with the permission granted to Office online to access Dropbox files?

Poll
Do you work or study in the creative industry? If so, which area?
If you use Adobe, don't forget to check out our latest integrations update here.
Who's talking

Top contributors to this post

What do Dropbox user levels mean?
Need more support?