During a response to this post (
https://forums.modx.com/thread/78573/css), the topic of the security of files within a Media Source directory came up. It was quite clear that there is still ambiguity regarding what happens when a request is made to a URL within a Media Source directory.
The possibility that MODX invokes no security protocols on these files was the understood behavior. That is, a direct URL request to the file would result in no security parameters being checked. Is this indeed the case? If this is the case, what can be done to harden security to media source files (without modifying the source).
For clarification: information on the actual behavior is important to me. Information on hardening would pertain to others who might not know how to harden their systems.
-
☆ A M B ☆
- 24,524 Posts
If you are really concerned about the security of files to be made available to valid users, it might be best to store them as BLOBs in the database, and serve them via a PHP stream.
Any file in the filesystem that is not protected by the web server will be accessible via URL from the browser. MODx code is protected by various checks for SESSION values and/or other constant variables set by the including scripts (index.php to begin with). These files can in fact be accessed, they just die immediately if the validation checks don't clear.
My technique for this is to again utilize the OnPageNotFound and serve the file that way. This way a request goes directly through MODX, but I don't have to store BLOBs. I have also found a technique to store images and similar data as Resources and serve them directly, but this is a convoluted process and I don't use it actively. (It was purely for theoretical exploration). If there is interest, I may write a tutorial on both methods.
@Sottwell:
I don't think the concern here is for valid users, but really for situations where you cannot determine the validity of the user (such as a direct URL request that does not invoke MODX). If a URL Request to a Media Source does not, in fact, invoke security in MODX, there are very few well known security measures for those who do hold sensitive information that still needs to be accessed via MODX pages. This is why I think this thread might be important for others. I don't do client work any longer, but when I did, I know that security for specific data in files often came up. (I wasn't using MODX at the time, however).
NOTE: I rarely use the file system, so these are the only two methods I have explored, but the first has been useful so far.
[ed. note: fuzzicallogic last edited this post 14 years, 1 month ago.]
-
☆ A M B ☆
- 24,524 Posts
I have one client where this sort of thing was necessary, so I protected the directory with .htaccess and .htpasswd and the client has that extra layer of password protection. They're happy with it; it makes them feel secure. Again, internal PHP use isn't affected, as it doesn't go through the Apache server.