password protecting files that have been uploaded for members
Posted: 02 December 2008 12:45 PM   [ Ignore ]  
Summer Student
Total Posts:  14
Joined  11-18-2008

Hello,

I have one security issue which i am struggling to get around on a site I am building for a client.

A user of the website who is not logged on or is not an authorized member of
the website can access files and resources I have uploaded to the members area of the site.

You have to log into the members area to see the list of files, but an unlogged user could potentially access the files by accessing the url of the file directly if they knew it/guessed it etc…

This is a worry for my client, and I was hoping someone here might be able to point me in the right direction towards a solution.

These forums have been very helpful to me in developing the website in expression engine so far, so thanks a lot to all the posters and answerers!

Thanks,
Inge

Profile
 
 
Posted: 02 December 2008 01:58 PM   [ Ignore ]   [ # 1 ]  
Moderator
Avatar
RankRankRankRankRank
Total Posts:  2828
Joined  01-07-2008

Hi Inge,

Welcome to the forums smile .

There is currently no native way of doing this.  You may want to look at the linklock module to see if it fills your need.  I’ll move this to how-to to get some more eyes on it.

~pascal

 Signature 
Profile
MSG
 
 
Posted: 02 December 2008 03:38 PM   [ Ignore ]   [ # 2 ]  
Professor
Avatar
RankRankRankRankRankRankRank
Total Posts:  10830
Joined  04-15-2006

The Linklocker module is definitely a great way to go on this one as Pascal has said.

Another thing you might want to look into are the in-built Template Access Restrictions where you can make it so that a non logged-in user can’t access a certain template until they log in.

That might help too on this one if you just want to stop non-logged in users from viewing the template.

Best wishes,

Mark

 Signature 

Shopping Cart Plugin
Full list of add-ons
———————————————————-
Buy me a drink, or two if you like!!

Profile
 
 
Posted: 03 December 2008 09:46 AM   [ Ignore ]   [ # 3 ]  
Summer Student
Total Posts:  14
Joined  11-18-2008

Thanks for your replies Pascal and Mark . smile

I had been trying a few other methods without success including all sorts of messing with the .htaccess files etc, having had a look at the Linklocker module it looks like the thing.

As far as I can see I would need to purchase the commercial version rather than the free one, so one quick question before I go ahead:

The admin user in this instance can upload members-only files in the publish form on a few particular pages but they tend to add links throughout the body text, rather than in a particular custom field. 

As I can’t really anticipate how many links the admin user will want to put on a given page, I’m not certain about using custom fields for this purpose. Does the Linklocker module require the link to be placed in custom field?

Thanks again for your input.

Profile
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1743, on December 02, 2009 03:47 PM
Total Registered Members: 120438 Total Logged-in Users: 65
Total Topics: 126529 Total Anonymous Users: 43
Total Replies: 665317 Total Guests: 380
Total Posts: 791846    
Members ( View Memberlist )