Hi There,
I have a couple of secured areas on my site. None of the information is super sensitive but it would still be good if people could not send a direct link to a file and subsequent people who click on that link simply get access to the file without having to log in to the authorised areas. It makes my clients feel happier if people cannot do this.
I have read a few ways of doing this - disguising URLs, using .htaccess etc, and also putting the folder outside the root. I'm not really sure how to do that and have users be able to upload files into the folder. TinyMCE only wants web users to put files in the assets/files directory. So maybe the best solution for me is simply to disguise the URL so that if a user sends a link, the link itself is disguised before they send it - so if the file is in sitename/assets/files/members/file.pdf the link gets sent as sitename/authorisedarea/ or something like that.
I've read a few things but they are a bit confusing - involving plugins and such that I'm not sure deliver what I want in the end. Does anyone have a solution or know of a thread that simply explains what should be done in cases like these? I know it can be done - would it be better for me to store the files in the database? Is there something that does that already?
Thanks for any help,
Kathy