[solved] [FC 1.5.x] secure files above DocumentRoot

More
13 years 10 months ago #8672 by bittingbits
Hi there,

Looks like the "Path to secure files folder" in the general settings does not accept absolute paths to directories above / outside the DocumentRoot.
If so, in which way is the "secure" option more secure than the default one? What sort of protection is actually added?
From my experience with other scripts allowing secure downloads, the only feasible method to actually prevent hot linking and keep files away from prying eyes is by placing the files above the DocumentRoot.

For intra and extranets where highly confidential data is moved, any solution which does not contemplate what i have just described might be delusional and compromising.

An explanation and possible workarounds would be much welcome.

Please Log in or Create an account to join the conversation.

More
13 years 9 months ago #8749 by bittingbits
This is an outstanding issue we are willing to address ourselves.
Would be interesting to add this to the dev branch once we finish it.

Please Log in or Create an account to join the conversation.

More
13 years 9 months ago #8773 by micker
cool thanks for devellopping for this project
regards

FLEXIcontent is Free but involves a very big effort on our part.
Like the our support? (for a bug-free FC, despite being huge extension) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing reviews. Thanks![/size]

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23692 by hede
Hello!

Did this development take place? Is it now possible to store files outside the joomla directory? Thanks.

FF on Win10, FLEXIcontent version 3.0.10 on Joomla 3.4

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23697 by micker
i didn't think ... :oops:

FLEXIcontent is Free but involves a very big effort on our part.
Like the our support? (for a bug-free FC, despite being huge extension) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing reviews. Thanks![/size]

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23701 by ggppdk
The download field plugin:
(a) checks access level of the user before it allows downloading, and
(b) also does not reveal the location of the file (it can reveal the filename if you allow),

So you can do these:

1. change secure folder in Global config
2. rename folder via ftp
3. -optionally- you could also add an .htaccess file with password inside the folder

you are done,
people will never know the real location of the file, and if they do find URL in some way, they will not be able to download it, because it is protected by the web server.

I guess we could automate the above 3 steps
, randomizing the folder name and adding an .htaccess in the folder with some random password (will work for apache servers only)


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star...

Please Log in or Create an account to join the conversation.

Moderators: vistamediajoomlacornerggppdk
Time to create page: 0.575 seconds
Save
Cookies user preferences
We use cookies to ensure you to get the best experience on our website. If you decline the use of cookies, this website may not function as expected.
Accept all
Decline all
Essential
These cookies are needed to make the website work correctly. You can not disable them.
Display
Accept
Analytics
Tools used to analyze the data to measure the effectiveness of a website and to understand how it works.
Google Analytics
Accept
Decline