Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: [Closed]: Control Access  (Read 5243 times)

0 Members and 1 Guest are viewing this topic.

w000f

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
[Closed]: Control Access
« on: June 12, 2008, 10:08:16 pm »

Hello,

Is there a way to not allow anyone to get to pictures by knowing the filename and the directory it is in? My galleries are only viewable by having to login (no public access). However, if you view it once and know the directory and filename, you can get to it by typing in the url, bypassing the login. Is there a way to prevent that?

Example - if you know the url:

http://xxx.com/albums/userpics/1000x/img001.jpg

You can type it in to view the pictures.

Thanks.
« Last Edit: June 25, 2008, 07:05:06 pm by Joachim Müller »
Logged

Fabricio Ferrero

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Male
  • Posts: 1996
  • From San Juan, Argentina, to the World!
    • http://fabricioferrero.com/
Re: Control Access
« Reply #1 on: June 13, 2008, 12:12:32 am »

Yes, there is.  ;) But it's not coppermine related. Google for hotlink protection.
Logged
Read Docs and Search the Forum before posting. - Soporte en español
--*--
Fabricio Ferrero's Website

Catching up! :)

w000f

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: Control Access
« Reply #2 on: June 14, 2008, 10:24:16 am »

I found more info but it appears that hotlinking protection via .htaccess is the next best thing at the moment since files access control is not part of the core.

Is this a correct way?
Code: [Select]
Options -Indexes
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?gallery.chipmunkfamily.com [NC]
RewriteRule \.(jpg|jpeg|png|gif)$ - [NC,F,L]

Image still viewable - http://gallery.chipmunkfamily.com/albums/Acura%20TSX%20-%20March%202004/etsx01.jpg

I know I'm not doing it right. What is wrong? Appreciate any help I can get. Host do support rewrite - even list it on the hosting FAQs.
Logged

just_some_guy

  • Supporter
  • Coppermine addict
  • ****
  • Offline Offline
  • Posts: 539
  • I am currently on holiday, back in a few weeks. :D
Re: Control Access
« Reply #3 on: June 14, 2008, 10:45:23 am »

Seems to be working fine for me - I get a 403 Forbidden error.
Logged
Tambien, Hablo Español      PHP - Achieve Anything
"The Internet is becoming the town square for the global village of tomorrow. " - Bill Gates
Windows 7 Forums

w000f

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: Control Access
« Reply #4 on: June 14, 2008, 11:06:09 am »

Hmm... well I initially thought it was the browser cache but I cleared it many times already.  ??? Let me try again.
Logged

w000f

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: Control Access
« Reply #5 on: June 14, 2008, 04:42:53 pm »

I see how it works now. :( Click on the link it says forbidden. Copy, paste the URL and you will see the pictures. Any other codes I can put in the .htaccess to disallow that? Please know that I understand the argument of - if you want your pictures to be secure, do not put it on the Internet. With the availability of users and groups, this should not happen.

Thanks.
Logged

Nibbler

  • Guest
Re: Control Access
« Reply #6 on: June 14, 2008, 06:04:35 pm »

Remove this line.

Code: [Select]
RewriteCond %{HTTP_REFERER} !^$
It's not a good solution though. There is nothing you can do about direct linking since it bypasses Coppermine entirely.
Logged

w000f

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: Control Access
« Reply #7 on: June 15, 2008, 05:01:40 am »

Thank you Nibbler. Removing that line now shows the forbidden page as well when you past the URL into another browser window. Is this something that will be worked into version 1.6.x? Just curious.

Thanks.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Control Access
« Reply #8 on: June 22, 2008, 11:07:10 am »

Is this something that will be worked into version 1.6.x?
Next version will be cpg1.5.x, not cpg1.6.x. As Nibbler pointed out, this can not be built into Coppermine, since it bypasses Coppermine. You'd have to store the pics outside of the webroot (one level up) and dynamically generate a temporary copy of the file the legitimate visitor can see that needs to be purged after a certain time if you wanted to accomplish what you're up to. This would cause a huge performace penalty and will make Coppermine very hard to set up and will therefor not go into coppermine any time soon. This has been discussed in detail in previous threads already, so I won't explain this any further - search the board for details if you want to find out more.
Logged

w000f

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: Control Access
« Reply #9 on: June 25, 2008, 04:39:10 pm »

Thank you.

W.
Logged
Pages: [1]   Go Up
 

Page created in 0.021 seconds with 16 queries.