Skip to content

Downloads API (v1) returns release files for "hidden" releases #1308

@jaap3

Description

@jaap3

While trying to recreate a realistic downloads section for local pythondotorg development I noticed that the following.

The API v1 downloads release_file endpoint lists a number of files that refer to a release that seems to be hidden:

Accessing these release endpoins results in a 401 Unauthorized response.

I'm not sure what's the cause of this, but it seems that these files should not be listed (publicly) if the release is made unavailable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    app/downloadsRelates to the downloads app

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions