Hi,
I have a small problem with a customer.
The website has a member access, within several docs only for the members (ie. pdf).
I have set a media source called "Members" with a path to /assets/docs/members/
But when you are not logged as Members, you can access to a file inside the /assets/docs/members/ directory if you know the name.
How can I avoid this and protect every file inside this Media Source for anyone else which are not autorized ?
-
☆ A M B ☆
- 24,524 Posts
Odd, I heard this from others as well, but (unusually for my location) I had no problem with it all day.
-
☆ A M B ☆
- 24,524 Posts
To protect files in the web space from being accessed directly you have to use .htacces to deny such external, URL-based access. But that means nobody can access it, so you have to make the files available through some form of internal (server-based) file streaming method, such as include or file_get_contents. There are several file-handling snippets to do this. And this is also what static resources do - they use a PHP streaming function to fetch the file.
$content = file_get_contents($file);
Binary static resources also set the appropriate headers to stream the file to the browser.
I am using the fileDownload snippet and would love to "hide" the location of the resources to keep users coming to the site to download vs. linking.
-
☆ A M B ☆
- 24,524 Posts
I believe that fileDownload streams the files, so you should be able to protect the directory with an .htaccess entry; that is, if your site is hosted on an Apache server.