Support

Support is part of Event Gallery Extended.

Please get a subscription if you need support. Feel free to use the ticket system or the contact form for reporting defects or pre-sale questions. Make sure you're logged in in order to be able to create a new ticket.

For general information you can also jump to the manual.

Subscribe now!

#827 all photos downloadable for free

Posted in ‘Event Gallery - General’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Latest post by dsart on Friday, 04 July 2014 08:44 UTC

dsart
 the gallery works good, bur got a secure issue, all the uploaded photos without watermark are stored in http://www.website.com/images/eventgallery/gallerydirectory/
when a customer use the url manual with the imagenumber (http://www.website.com/images/eventgallery/gallerydirectory/imagexxx.jpg) they can download the photo for free, without the use of a pasword or using the cart.
So is it possible to protected this directory or where can i change the location of the directory so i can place them outside the root. We run our own server, so it is possible to go ouside the root.

thanks

sbluege
Event Gallery 3.3. will automatically add a .htaccess file which prevent access to those files.

If you don't use the social sharing you can do this manually for the current version.

sbluege
just in addition: another way is to use random file names which are hard to guess.

dsart
a idea when you release 3.3?

i'm on IIs 7.5, so i have also tried set url rewrite, but then the plugin gives a 404 error.

In the mean time we use watermarked pictures as original.
Becouse you didn't answer the question of placing the folder outside the root, i gues it isn't possible.

thanks

sbluege
I'm very sure that even IIS can protect folders.

I can't give a timeline for 3.3 but 3.2 is already available with a subscription. The free release will follow in some weeks.

With Event Gallery 3.2 you can move the image folder. There is a config.php file which contains some instructions. Since the social sharing uses the original files you can't share those images if you remove web access from this folder. Also it'll reveal your secret folder since it publishes to url.

The best way for you is to deny access to this folder and disable the social sharing.

dsart
thanks for the fast reply, we go to use the social media as a 'publicity' channel, so a basic watermark on it will be good. We don't like give away our original files, So we go to use origialfiles with a watermark. Till we find another solution.
Direct download of the files is not necessary at the moment, Because we sell the files in the 3 formats (LowRes, Normal Res and High Resolution) After ordering the digital files we prepare the files and let them download from a another location.

thanks