[solved] [FC 1.5.x] secure files above DocumentRoot

More
12 years 1 month ago #23702 by hede
Thank you. That is a good solution for my site.

FF on Win10, FLEXIcontent version 3.0.10 on Joomla 3.4

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23711 by ggppdk
Also , since you are changing the folder you can try placing it above your public_html and using something like ../mysitefiles, if your joomla installation is directly inside public_html, then above will place your folder at the same directory as public_html, preventing direct access without need of .htaccess

Please note that the above steps are needed, but are not enough to provide protection from hot-linking if access to your download field is public

in such a case someone can still hot-link to your files by adding links pointing to the download field urls.

mmm more is need, we need to also use USER SESSIONs, this will make difficult to hot-link to your urls, since someone must first visit your site and display a page containing the download link, before he can download the file.

I say very difficult because despite what some sites say, it is possible to bypass this too, since some could do this via javascript at the user browser (retrieving your page open a guest session) and then redirecting to your download link. Of course you can make this even more difficult by randomizing the download links URLs !!!

In short it is possible and it is even possible to do even for register users, but don't worry, the user session solution is almost always enough

Regards


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star...

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23717 by hede
Thank you. So with the .htaccess in the "secured" folder and the download links visible only to logged in users, the files are save from getting downloaded directly?

FF on Win10, FLEXIcontent version 3.0.10 on Joomla 3.4

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23720 by ggppdk
Yes but do not forget to set the access level of your download fields to "registered", if you FLEXIaccess then you can have more user groups than just all registered users.

For your .htaccess remember to set a username / language pair, e.g. read here:
www.addedbytes.com/lab/password- ... -htaccess/


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star...

Please Log in or Create an account to join the conversation.

More
12 years 1 month ago #23731 by hede
Thank you. I think now Im sorted.

FF on Win10, FLEXIcontent version 3.0.10 on Joomla 3.4

Please Log in or Create an account to join the conversation.

Moderators: vistamediajoomlacornerggppdk
Time to create page: 0.293 seconds
Save
Cookies user preferences
We use cookies to ensure you to get the best experience on our website. If you decline the use of cookies, this website may not function as expected.
Accept all
Decline all
Essential
These cookies are needed to make the website work correctly. You can not disable them.
Display
Accept
Analytics
Tools used to analyze the data to measure the effectiveness of a website and to understand how it works.
Google Analytics
Accept
Decline