PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |
Old August 17th, 2005, 12:24 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
users can access images directly but shouldn't be able to

I just noticed today that if i change "gallery/files/1/picture_thumb.jpg" to "gallery/files/1/picture.jpg" I can access the full size image. I have my permissions set up properly and the .htaccess setting set to ON. How can i prevent a user from accessing the image this way without moving all my files into the database?

thanks
eric
Happy Camper is offline   Reply With Quote
Old August 20th, 2005, 02:34 AM   #2 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
Re: users can access images directly but shouldn't be able to

anyone?
Happy Camper is offline   Reply With Quote
Old August 20th, 2005, 12:49 PM   #3 (permalink)
Brian
Guest
 
Posts: n/a
Re: users can access images directly but shouldn't be able to

There's really not a way to fully protect your images without having them in the document root, which should be an option in the next version of the gallery.
  Reply With Quote
Old August 20th, 2005, 06:10 PM   #4 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
Re: users can access images directly but shouldn't be able to

thanks brian
Happy Camper is offline   Reply With Quote
Old August 21st, 2005, 02:15 PM   #5 (permalink)
Brian
Guest
 
Posts: n/a
Re: users can access images directly but shouldn't be able to

Small correction, I meant to say "below the document root", not "in the document root".
  Reply With Quote
Old August 28th, 2005, 07:59 AM   #6 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
Re: users can access images directly but shouldn't be able to

one question about the images being stored below the document root: when a user views the full-szed image (one of which that is being stored outside the public_html) will they ONLY see the image or will they see the page header, info about the image, the page footer, etc?

im just curious because i have been playing around with storing/displaying images from below the root and it seems after you serve the image you can't send any html to format the page whatsoever.

eric
Happy Camper is offline   Reply With Quote
Old August 28th, 2005, 12:57 PM   #7 (permalink)
Brian
Guest
 
Posts: n/a
Re: users can access images directly but shouldn't be able to

If they're moved below the document root you can still display them with an <img> tag that points to displayimage.php.
  Reply With Quote
Old August 28th, 2005, 05:39 PM   #8 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
Re: users can access images directly but shouldn't be able to

right, but will you also be able print other things, such as the image name, filesize, replies, etc after you have declared the various header(Content-...) that you will need to server the image?

i hope that makes sense...
Happy Camper is offline   Reply With Quote
Old August 29th, 2005, 07:26 AM   #9 (permalink)
Brian
Guest
 
Posts: n/a
Re: users can access images directly but shouldn't be able to

Yes. It doesn't matter whether the <img> tag points to a .php file or an image, the rest of the page is still exactly the same.
  Reply With Quote
Old August 29th, 2005, 07:34 AM   #10 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 92
Re: users can access images directly but shouldn't be able to

cool! i heard that was impossible so i'll need to figure that out. if you could point me to any resources/tutorials that you know of on how to do that I'd really appreciate it. If you're not too busy, of course.

thanks
eric
Happy Camper is offline   Reply With Quote
Old August 29th, 2005, 07:43 AM   #11 (permalink)
Brian
Guest
 
Posts: n/a
Re: users can access images directly but shouldn't be able to

Look at your displayimage.php file with the gallery.
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Registered Users getting Admin Access ace67 ReviewPost Installation & Upgrades 4 October 19th, 2005 10:58 AM
# of users who can access vbadvanced iceit69 Before You Buy 1 April 21st, 2005 11:08 AM
deny access to images citra How Do I? - vBulletin 3.0.X 1 March 18th, 2005 03:07 PM


All times are GMT -5. The time now is 12:28 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0