I’m trying to implement FancyUpload on my page. My problem is that I wan’t to use the snippet on a non-public page and that I don’t really understand how the frontend-/backend pages should be used. Should both pages have access-restrictions? Everything works if I make the page public.
Thank’s in advance
Kristoffer
The public pages always work. The frontend/backend is like a decoy : The frontend page will be with your custom (private) permissions, while the backend page should have public permissions. It’s the backend who’ll do the real upload, but it will check the permissions of the frontend page.
This is working great in firefox, but I can’t get the mootools version to work under IE6 or 7.
The attached screencapture is what I get in either version of IE:
Do I need to use the Uploadswitcher or something to force that mode in IE?
I saw a post by TXRX that shows it with the right "Browse Files" button that allows for multiple file selection, mootools, etc.
Any hints as to how you did it TXRX?
Any thoughts on where I can look (which areas of which files) to troubleshoot my inability to upload files?
FancyUploader shows 100% complete, but I check the folder through ftp and do not see the files uploaded to the folder I’ve specified or anywhere else for that matter.
It does work on a local copy of my site that I created to test this and see if it was a problem with my host. So it does look to be a problem with my host, but I’ve changed the permissions for the folder I want to save to (assets/files/) and the parent folder to 777 and still no success.
I know this isn’t a problem with the snippet, but I’ve been tracing through the java files and the snippet trying to figure out where it’s going wrong and can’t get anywhere. Any one else have any experience along these lines?
Hi,
I was going to (try!) to create a snippet like this, but I see it is already made (my php skill are slim, so I don’t know if I could have done it, so thank you!). A few questions though:
Forgive me if I’m asking a bit of a dumb question, but I’m unsure on the purpose of the "backend" for a non-public page. Is this because session cookies are not sent with ajax calls, so the "non public" page wouldn’t be accessible, so the snipped wound’t run? Would it be possible to read the session cookie using javascript, send it in the http header of the file upload, and thus eliminate the requirement for the backend page?
Michal.
Yes, it’s that way, and I think it’s possible. But it will need more code modification. The goal of the FancyUpload snippet was just to use the FancyUpload, with a little or no change at all.
I think it’s possible to bring session cookies to the JS, and then use them to allow the JS to access the page like a classic webuser. But I’m not sure about security (Send cookies :s) and all that stuff.
Due to the fact I’m not that good at coding, I chose to trust the base modx authentication system :p
Feel free to modify it if you like, but I can’t work on that for the moment, I’m really busy on a project, sorry :s
-
☆ A M B ☆
- 1,231 Posts
I wonder if this is possible...
A user signs up to your site... a folder is created with their username as the the name of this folder and only they would have permission to it. And using your FancyUpload script, being able to upload to that folder only. That would be awesome!
Anyway, great snippet.
Ross
-
☆ A M B ☆
- 24,524 Posts
Don’t see why not... use a plugin to create the folder. Use a snippet to determine the loggen-in username and use that snippet as a parameter to the upload snippet to specify the folder to upload to.
As far as permissions to the folder in the filesystem itself, that would still be set to the user the script is running as. But access from web pages would be managed by snippets checking the SESSION values for the logged-in user.
I did much the same thing for database access; the AJAX query to the database to populate a table is filtered by the logged-in username to only return that user’s data.
I think it could be more flexible if you choose to use a TV for upload folder then. You could set your tv to @EVAL (getting the folder by username or in simply the database) or simply use a static TV for all uploads.
Nice idea!