Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsForm and ListForm and ListImages in a UDT and securityImages in a UDT and security
Previous
 
Next
New Post
4/26/2008 10:24 AM
 
The docs for the UDT Image column say:
…or select an image stored in a non-secure folder on the portal where the user has access. The user will be presented with non-secure folder access regardless of the user’s permission.
Exactly what does this mean? For instance does this mean:
1)      An Internet user can somehow access the image files outside the website?
2)      A DNN site user can access the image files w/o being logged in even is the UDT is on a secured page?
Please explain.
 
New Post
4/26/2008 10:35 AM
 

Any file in an insecure DNN folder can be downloaded by a user just by entering the URL into the browser's address bar - though this requires the user to know or be able to guess the URL. Files in DNN secure folders are not delivered when entering the file name.

If you provide a direkt link like /portals/0/myfolder/myfile.txt, anyone can download the file by clicking it in the module, bypassing DNN folder security. you cannot provide a direkt link to files in secure folders. If you provide a link to a local file via fileID (using the URLcontrol to select it), the file will be delivered by linkclick aspx http handler only, if the user has view permission for the folder, regardless of the file resinding inside a secure or insecure folder.


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
4/27/2008 9:50 PM
 
2 follow-up questions:
1)      Why aren’t images stored in a secure folder?
2)      You have lost me in the 2nd paragraph of your response. You seem to contradict yourself.
 
New Post
4/28/2008 5:19 AM
 

sorry, images are not taken from secure folders, because this would require an additional overhead in the module, for which we did not see a real need.


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
4/30/2008 8:02 AM
 
There defiantly is a need!
For instance I’m working with a church that wants to put their membership directory on their DNN site. The UDT module with the CardView  XSL is perfect, but there are concerns about the security of the members personnel information. Subsequently the directory will only be accessible to church members that are of course registered users. But what you are telling me is that the images ultimately can’t be secured.
So what can be done to limit the chance these member photos could be accessed by non-members with malicious intent?
 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsForm and ListForm and ListImages in a UDT and securityImages in a UDT and security


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out