Hacker News new | ask | show | jobs
by jeroenhd 401 days ago
You might not want to use https://anydocai.com/result/<incremental number> for URLs like that. Anyone can enumerate the ~300 files from the home page and look at what others have uploaded.

That said, the website doesn't seem to work anymore. It just errors out.

3 comments

Also, as far as the enumeration users are only authorized to access the files that they’ve created in our system, but I should definitely obscure the file count
I’m like a mid-level developer though so if I messed up the authorization access and you worked around it in someway if you let me know that would be sick @boshjerns on X
I didn’t expect this to go semi viral on here so I just refilled the credits. It actually ran out of credits for open AI.
gemini is cheaper, probably
I wonder if they ran out of credits.
Yeah, this is exactly what happened. I did not expect this or catch up until just now, but I just fixed it.