Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 01:12:39 AM

Login with username, password and session length
Search:     Advanced search
Interested in joining the WebsiteBaker team?
For more Information read here or on our new website.
155533 Posts in 21713 Topics by 7738 Members
Latest Member: Pattieardathfe
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: Access control on Media folders?  (Read 911 times)
klilleng

Offline Offline

Posts: 5


« on: October 19, 2009, 10:05:07 AM »

Hi!

Just installed websitebaker, and really like it. One thing however, may stop the deployment.
It seems there are no access control on the Media folders?
So if you have a direct link, you can access any file, even on someone else's Home Folder?
Is this correct? Are there any ways around this?
I need to have private files for each user, that no one else can open or view.

Thanks. smiley
Logged
Luisehahne
Board Member
Development Team
*****
Offline Offline

Posts: 3147



WWW
« Reply #1 on: October 19, 2009, 10:24:44 AM »

Hi,

I just tested on my Installation

Quote
Forbidden

You don't have permission to access /wb/media/random/ on this server.

and if i try to call the /media/ it's call the startpage.

Pls check your permission

Dietmar


« Last Edit: October 19, 2009, 11:12:24 AM by Luisehahne » Logged

We are human beings - and nobody is perfect at all.
klilleng

Offline Offline

Posts: 5


« Reply #2 on: October 19, 2009, 02:13:00 PM »

You have to try with a file, like
 /wb/media/random/myfile.pdf

(the file must of course exist in this location)

Thanks.
Logged
Luisehahne
Board Member
Development Team
*****
Offline Offline

Posts: 3147



WWW
« Reply #3 on: October 19, 2009, 02:38:12 PM »

Quote
Not Found

The requested URL /wb/media/Autumn_lake_1024 x 768.jpg was not found on this server.

My permissions mode for folder are 755

Dietmar
Logged

We are human beings - and nobody is perfect at all.
klilleng

Offline Offline

Posts: 5


« Reply #4 on: October 19, 2009, 02:56:55 PM »

Hmmm strange. Ok, but can you access this file through a link when logged in (that is, a regular URL, not by the Media option)?
Logged
LordDarkman
Development Team
*****
Offline Offline

Posts: 343


WWW
« Reply #5 on: October 19, 2009, 04:48:06 PM »

It is possible. sometimes I share files with others, so I just upload them to media folder and give them the link. as example
http://lorddarkman.de/web/media/wb1171.zip
If you don't want this to happen put a .htaccess into your media/userfolder witch doesn't allowed external access. But maybe you have than problems in viewing the contend in this folder without login in (htaccess login not wb).

CU Moritz
Logged
klilleng

Offline Offline

Posts: 5


« Reply #6 on: October 19, 2009, 05:40:39 PM »

Yes, adding a .htaccess could resolve this issue, but then I guess I'd have to manage htaccess authentication and users, in addition to WB users. And users would have to "log on" twice. It's not very tempting.
Logged
LordDarkman
Development Team
*****
Offline Offline

Posts: 343


WWW
« Reply #7 on: October 19, 2009, 08:30:12 PM »

but I think it's the only posibillity. If you know a filename it's allways possible to access this file. But who knows them? Normally no one. And if you try to access the folder you get a redirect to the start page.

CU Moritz
Logged
klilleng

Offline Offline

Posts: 5


« Reply #8 on: October 20, 2009, 03:58:03 PM »

In my case it would be possible to guess the filenames of other users, by looking at your own. And I don't want to obscure the filenames with exotic renaming. smiley. The grand idea is to have some sort of invoice filestore, where each user only sees his invoice-files. Seen at several CMS'es, but they seem to lack the possibility of setting individual user rights on files/folders like I want to. Might have to look at other kind of apps, I guess.
Logged
pcwacht
AddOn Development
*
Offline Offline

Posts: 2859



WWW
« Reply #9 on: October 20, 2009, 05:24:27 PM »

In that case you need something wich puts the files in the database, or outside the html rootdir.

There is nothing simular yet for WB.

John
Logged

http://www.ictwacht.nl = Dutch ICT info
http://www.pcwacht.nl = My first
both still work in progress, since years.....
KM-Linux

Offline Offline

Posts: 6


« Reply #10 on: January 17, 2010, 08:45:37 PM »

Do you know, if something is planned to fix the problem?
I noticed it today too.
Logged
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!