Drupal private file mystery -- who has access?
What is the default drupal private file/image field behavior? It is a mystery. Is it only for authenticated users? Will it ever be visible publicly?
For more context, we are talking about files found in system/files/*
.
Here is the short summary (TLDR):
If you have access to view the content, then you can view the private files attached to it.
Some scenarios: