Private Files: Prevent cross-site lookup
23:59:06 GMT+0000
In a multisite install, we support running mixed private and public sites. To harden our ACL endpoint and prevent accidentally leaking private files via public sites, we now restrict access to files on the same subsite.