Attachments can be Downloaded without Authenticating when Using a Force.com URL
|Knowledge Article Number||000206698|
|Description||Users are able to download attachments associated with objects in the Community without first logging into that Community.
This occurs when:
Example URL: https://customdomain.force.com/servlet/servlet.FileDownload?file=00Pxxxxxxxxxxxx
In this URL, replace 'customdomain' with the custom domain for your Community, and the 00Pxxxxxxxxxxxx with the record ID for the attachment.
|Resolution||To instead route the URL to the Community login page, Read access for the Community's Guest Profile must be removed from the object in which the records reside.|