Sensitive Data / Acess files via direct URL without login

Phoca Download - download manager
sunconcept
Phoca Newbie
Phoca Newbie
Posts: 4
Joined: 12 Nov 2018, 13:41

Sensitive Data / Acess files via direct URL without login

Post by sunconcept »

Hi Guys,

I have sensitive Data in my Phoca Download, which can only be accessed via logged in users.

However, I found out, that if you know the exact path to the files, you can allways type it into your browser and access the files as a guest and dont need to login.

How can I change this? The files should only be accessable via login and via Phoca Download.

Greetings
Tobias
User avatar
Benno
Phoca Hero
Phoca Hero
Posts: 9112
Joined: 04 Dec 2008, 11:58
Location: Germany
Contact:

Re: Sensitive Data / Acess files via direct URL without login

Post by Benno »

sunconcept
Phoca Newbie
Phoca Newbie
Posts: 4
Joined: 12 Nov 2018, 13:41

Re: Sensitive Data / Acess files via direct URL without login

Post by sunconcept »

Hi Benno,

thanks for the reply. But we can't get aut of the public_html folder on our hosting.

Is it enough to put a htacess with

Order deny,allow
Deny from all

in the folder?

Greetings
User avatar
Benno
Phoca Hero
Phoca Hero
Posts: 9112
Joined: 04 Dec 2008, 11:58
Location: Germany
Contact:

Re: Sensitive Data / Acess files via direct URL without login

Post by Benno »

Hi,
I'm not really an expert in these things. Try it... :idea:

Kind regards,
Benno
sunconcept
Phoca Newbie
Phoca Newbie
Posts: 4
Joined: 12 Nov 2018, 13:41

Re: Sensitive Data / Acess files via direct URL without login

Post by sunconcept »

HI Benno,

thanks for the support. It works with the htaccess solution.

I have another short question.

I have phoca download configured only for registered members. But they are seeing all categories, also the ones which the dont have permission. Is it possibly to configure that they only see the category (for what the have permission)?

Greetings
Tobias
User avatar
Benno
Phoca Hero
Phoca Hero
Posts: 9112
Joined: 04 Dec 2008, 11:58
Location: Germany
Contact:

Re: Sensitive Data / Acess files via direct URL without login

Post by Benno »

Hi,
Yes, this is possible. But you need to set 'Access Rights' individual for each registered user for each category.

Backend settings:
Image

Frontend: benno-test is logged in, who has 'Access Rights' to see this category:
Image

Frontend: Benno is logged in, who has no 'Access Rights' to see this category:
Image

Kind regards,
Benno
sunconcept
Phoca Newbie
Phoca Newbie
Posts: 4
Joined: 12 Nov 2018, 13:41

Re: Sensitive Data / Acess files via direct URL without login

Post by sunconcept »

I think I have done it this way... But I have only one menu item with a link to the overall category view. And it shows every categorie, even the ones which the user dont have permission.

- cat 1
- cat 2 (you only have permission here)
- cat 3

Greetings
Tobias
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 47870
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Sensitive Data / Acess files via direct URL without login

Post by Jan »

Hi, do you use some cache settings?

Jan
If you find Phoca extensions useful, please support the project
Post Reply