id,summary,reporter,owner,description,type,status,priority,milestone,component,version,resolution,keywords,cc
2112,Tmp Directory for Deluge-Web downloads,baconseed,damoxc,"While server.py in ui/web has the correct method of creating a tempdir, and using that tempdir to store files, json_api.py does not. This creates a big security risk for multi-user environments, as they end up in /tmp/ on Linux systems, readable by world. Attached is a patch to resolve this issue. It will create the tempdir, and use that to store torrent files, as is done in server.py",patch,closed,critical,1.3.6,webui,master (git branch),fixed,,
