We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18503
    • 45 Posts
    Yeah, the URL encoding for the "+" is "%2B" i think. I manually put "%2B" in the path instead of the "+" to test and see if URL encoding would help, and the page still just refreshed. But maybe i’m missing something... I’m not that familiar with URL encoding, would this test not be accurate?
      -dan
      http://wylio.com
      Wylio - Pictures for Bloggers
      • 21101
      • 169 Posts
      Quote from: OpenGeek at Jan 10, 2007, 07:22 PM

      Same problem here...it appears the FileDownload class creates the URL’s with a / instead of & if friendly urls are enabled. And there does not appear to be a way to control this in the snippet parameters...I’ve modified mine to remove this logic and generate it the same either way and it works fine.

      Change lines 340-344 of filedownload.class.inc.php:
      //					if ($this->_config['urlsetting'] == '?') {
      //						$fileLink = $this->_config['curUrl'].'/'.$filelocat . $multiFolderLink;
      //					} else {
      						$fileLink = $this->_config['curUrl'].'&d='.$filelocat . $multiFolderLink;
      //					}


      The variation with the / only works if you change your .htaccess as described in the FileDownloadPlugin instructions.

      oh yeah its working !!

      thanks wink
        Play no games
        • 36451
        • 264 Posts
        Please, can someone tell me: Is this script a plugin to the FileDownload snippet (I have to use it with that snippet) or is it a MODx plugin (I can use it stand alone)? Would be nice if it’s standalone, because it could handle secure download links in my normal float text, which I prefer over a "download table" of links and details.

        Short, is it a snippet plugin or a MODx plugin? And is it possible to use a download folder outside of the web root?
          • 15987
          • 786 Posts
          yoomai, it can be used independently of the FileDownload snippet. You just have to setup the TV and then create the links on your own.
            • 36451
            • 264 Posts
            Very nice plugin, guys.

            I’ve changed lines 340-344 of filedownload.class.inc.php like Jason has suggested. Works fine when I let FileDownload generating the links, but doing that manually seems to become very hard for my clients. The download path is outside of the web root for security reasons, so they can not simply click and point within the resource browser. Short, it would be nice to have the script itself providing not only the path (from the TV "FileDownloadFolder") but also the part before the filename, eg.
            [~[*id*]~]&d=

            Is that possible?

            Edit: Makes no sense, because this would probably affect every hyperlink on this page, whether it’s a download link or not. But it would be very helpful to have something like this in the "link list" dropdown inside of the TinyMCE "insert link" popup...
              • 4095
              • 372 Posts
              Two questions regarding the plugin,

              1. Is there a way to make this support multiple snippet calls on one page? Since I can only put the one path in the TV it breaks the other calls sad

              2. If someone guess or knows the full URL, they can still download the from a page in a protected area. So in that situation it doesn’t respect MODx’s security for the page. No doubt this is an issue with MODx not necessarily the plugin, but it does leave a bit of a security hole.

              Anyone got solutions?

                [img]http://www.emanz.ac.nz/assets/images/logo/emanz-icon_16x16.gif[/img] Emergency Management Academy of New Zealand [br] http://www.emanz.ac.nz[br][br]MODx Sandbox Login: sandbox Password: castle [br]
                Admin Sandbox Login: sandbox Password: castle
                • 18503
                • 45 Posts
                I’m not sure about #1, but for your second question, try changing the CHMOD settings on the folder that your downloads reside in to 744. This should make it still possible for the plug in to access the folder, but not a direct call from the web.

                Hope this helps!
                  -dan
                  http://wylio.com
                  Wylio - Pictures for Bloggers
                  • 4095
                  • 372 Posts
                  Unfortunately if its less than 774 the snippet gives an access / permission error and the page doesn’t load, although it does stop people from downloading the file smiley

                  When you set it to 774 (group execute), the page loads but back to the problem of anyone can download the file if they know the true path.
                    [img]http://www.emanz.ac.nz/assets/images/logo/emanz-icon_16x16.gif[/img] Emergency Management Academy of New Zealand [br] http://www.emanz.ac.nz[br][br]MODx Sandbox Login: sandbox Password: castle [br]
                    Admin Sandbox Login: sandbox Password: castle
                    • 22303 MODX Staff
                    • 10,725 Posts
                    The problem is of ownership I imagine. If you uploaded the file as your user account (i.e. not via a PHP upload form), but the web server is running as ’nobody’ or some other user account, the only way to have PHP access it and prevent web users from doing so would be to chown it to the user running the Apache/PHP process and then you can chmod it to 700.
                      • 4095
                      • 372 Posts
                      Sorry only got to working on the site again today. Been delivering courses (which is my actual job) every week, next week is the first time I spent a whole week in the office this year smiley

                      Your suggestion sorted it out, it was a user / group / permission combination issue. Now resolved..... great stuff !
                        [img]http://www.emanz.ac.nz/assets/images/logo/emanz-icon_16x16.gif[/img] Emergency Management Academy of New Zealand [br] http://www.emanz.ac.nz[br][br]MODx Sandbox Login: sandbox Password: castle [br]
                        Admin Sandbox Login: sandbox Password: castle