Yeah, the URL encoding for the "+" is "%2B" i think. I manually put "%2B" in the path instead of the "+" to test and see if URL encoding would help, and the page still just refreshed. But maybe i’m missing something... I’m not that familiar with URL encoding, would this test not be accurate?
Please, can someone tell me: Is this script a plugin to the FileDownload snippet (I have to use it with that snippet) or is it a MODx plugin (I can use it stand alone)? Would be nice if it’s standalone, because it could handle secure download links in my normal float text, which I prefer over a "download table" of links and details.
Short, is it a snippet plugin or a MODx plugin? And is it possible to use a download folder outside of the web root?
yoomai, it can be used independently of the FileDownload snippet. You just have to setup the TV and then create the links on your own.
Two questions regarding the plugin,
1. Is there a way to make this support multiple snippet calls on one page? Since I can only put the one path in the TV it breaks the other calls
2. If someone guess or knows the full URL, they can still download the from a page in a protected area. So in that situation it doesn’t respect MODx’s security for the page. No doubt this is an issue with MODx not necessarily the plugin, but it does leave a bit of a security hole.
Anyone got solutions?
I’m not sure about #1, but for your second question, try changing the CHMOD settings on the folder that your downloads reside in to 744. This should make it still possible for the plug in to access the folder, but not a direct call from the web.
Hope this helps!
Unfortunately if its less than 774 the snippet gives an access / permission error and the page doesn’t load, although it does stop people from downloading the file
When you set it to 774 (group execute), the page loads but back to the problem of anyone can download the file if they know the true path.
-
MODX Staff
- 10,725 Posts
The problem is of ownership I imagine. If you uploaded the file as your user account (i.e. not via a PHP upload form), but the web server is running as ’nobody’ or some other user account, the only way to have PHP access it and prevent web users from doing so would be to chown it to the user running the Apache/PHP process and then you can chmod it to 700.
Sorry only got to working on the site again today. Been delivering courses (which is my actual job) every week, next week is the first time I spent a whole week in the office this year
Your suggestion sorted it out, it was a user / group / permission combination issue. Now resolved..... great stuff !