Publishing a public link waits for a confirmed address

Sharing a document with named people works as it always has, whether or not the address on the account has been confirmed. Publishing one to a link anybody can open now asks for the confirmation first — on every route that can do it, which was the actual bug: two of the three were not asking.

Two kinds of sharing live behind one dialog and they are not the same act. Naming addresses publishes nothing: each reader has to sign in as the address you named, so the document is handed to people you chose. A link puts a page at /s/<token> on our domain that anybody holding the URL can read, and that is a page on the open internet with somebody else's content on it.

Why the second one is held back

An address nobody has proved cannot be recovered, cannot be told anything, and costs nothing to make a hundred of. A hundred of them publishing pages under our domain is the shape of a phishing campaign, and the domain is shared with everybody else using the product.

So two things wait for a confirmation and everything else does not: publishing to a link, and accumulating storage — an unconfirmed account keeps ten documents. Converting, downloading, the API, the connector and sharing with named people all work from the first minute.

Confirming it

A six-digit code from the account menu, good for ten minutes. Signed in through Google there was never anything to confirm: the provider asserts the address, so those accounts could always publish.

The check is read at the moment of the request rather than carried on your session, which means confirming takes effect on your very next request instead of your next sign-in — the behaviour anybody expects after typing a code.

Three doors, and two of them were open

A link can be published three ways: PUT /api/v1/documents/:id/share, POST /api/v1/documents?share=link, and the app's own PUT /api/documents/:id/share. Only the first of them asked. That is the actual fix here — the rule existed and had two holes in it, because a rule written three times is a rule maintained in one of them.

It is one function now and all three call it. A refusal is a 403 that says what to do: confirm the address, and note that sharing with named addresses works either way.

Related: sharing a document as a link, and whether an online converter is safe.