Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...File still visible, even though permissions set to disable for all usersFile still visible, even though permissions set to disable for all users
Previous
 
Next
New Post
7/27/2015 2:01 PM
 

I have a file in a folder that I don't want index or accessible without an authorized user role, mysite.com/test/document-02.jpeg

I went into file manager, and I set it so only registered users can view the /test/ folder, but this file document-02.jpeg remains visible without logging in.

How do I make this file inaccessible, and possibly redirect/prompt a login page if you aren't logged in or with an approved user role?

 
New Post
7/28/2015 2:40 AM
 

J N,

you have to set the permissions for that folder. Anyway, if the folder is not marked as "Secure" or "Database", anyone can still access it by entering the the exact Url of this file, this would propably be something like www.mysite.com/Portals/0/SomeFiles/AnImage.jpg.

When the file is in a secure or database folder, a file handler is needed (included in DNN) that checks the folder permissions. so the Url to that file would be something like www.mysite.com/LinkClick.aspx?fileticket=BsWxIL6KV5A%3d&portalid=0&language=en-US

Happy DNNing!
Michael


Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
New Post
7/28/2015 9:34 PM
 

I set the page and folder setting to secure, SSL is already set up and working fine, and the file is now hidden! Thank you!

Now the issue is that the image manager can't see the file; so I can't put it on any pages.  Any idea why that is?

I'm logged in as host, could that be the issue?  Does the image manager need some elevated permissions or something?

Is there a way to make all uploaded contents defaulted to upload to secured directories?

 
New Post
7/29/2015 7:21 AM
 

JN,

SSL is not necessary to access "Secure" folders. Files in these folders get an extra extension (".resources") that IIS does not deliver directly, so you don't have a chance to access it directly by www.mydomain/Portals/0/SomeFiles/AnImage.jpg.resources. DNN uses a handler (LinkClick.aspx) to get the file and deliver it to the browser.

I don't know which HTML provider you are using, so I can't tell you about the issue. If you are using the Telerik editor, try switching to CK Editor.

Host has the most elevated permissions in a DNN system. This does not work like Windows UAC :-)

The place to upload files using the HTML editor can be set by the user who uploads them (but of course, they need write permissions there). Therefore if you give them write permissions only to secure folders, they can't upload anywhere else. I don't know of any other way.

Happy DNNing!
Michael


Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
New Post
8/3/2015 12:22 AM
 
Thank you for the help! I think everything is operating as desired now.
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...File still visible, even though permissions set to disable for all usersFile still visible, even though permissions set to disable for all users


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out