Resources

My Agape try

Your Agape try


Support Forum

You must be logged in to post Login Register

Search 
Search Forums:


 




Attached files no longer private - eep!

UserPost

5:44 pm
March 10, 2010


sophvan

New Member

posts 1

1

I have a site running Wordress 2.9.2 with role scoper restricting most content to registered members only. There are a number of file attachments on the site that also need to be private and were till recently. I've upgraded to WP 2.9.2 and have upgraded role scoper to the most recent version and now (I'm not sure when this happened) if I enter the url of a pdf file that is attached to a restricted post, when I'm not logged into the site, I can see it.

When I set up the site originally I did some thorough testing to make sure these files could not be seen and I haven't changed the setup, so I can only conclude it's an issue with one of the upgrades (or upgrade of another plugin, I suppose).

I've been reviewing this forum and note that it appears the restrictions are done using htaccess entries?  Is there some way I can fix this quickly so my attached files are no longer vulnerable? What specificially is the correct code and which directory should it be in (home directory for wordpress or the uploads directory) My only other quick fix is to password protect my uploads directory, which defeats the purpose of having role scoper.

Thanks for your help,

Sophia


7:41 am
June 29, 2011


Kevin

Admin

posts 2503

2

This was fixed in Role Scoper 1.2. It was actually a combination of two different bugs:

1. Neither Post Restrictions nor Default Category Restrictions forced the protection of attached files. (but that protection was correctly forced with explicity assigned Category Restrictions or a "Private" Post Visibility, thus my difficulty in reproducing).

2. Some of the attachment filenames contained spaces, and Role Scoper's generated RewriteConds did not properly escape them. This caused generally unpredictable behavior - sometimes images seemed inappropriately blocked; sometimes inappropriately revealed. The revised code also escapes parentheses and other characters which would confuse the Rewriting logic.


About the Agapetry forum

Currently Online:

18 Guests

Maximum Online: 150

Forums:

Groups: 2

Forums: 7

Topics: 1245

Posts: 5653

Members:

There are 1255 members

There are 1 guests


Kevin has made 2503 posts

Top Posters:

metal450 - 178

Ragnar - 108

YikYak - 70

whiteorb - 49

Daisy - 35

Administrator: Kevin | Moderators: Kevin