[SOLVED] direct link to picture opens it even when "protected" by .htaccess

yhagger

Joined: 2011-10-27
Posts: 4
Posted: Sat, 2013-09-14 17:38

In the FAQ it says that my pictures are safe even when located under the var directory. (http://codex.galleryproject.org/Gallery3:FAQ#Are_my_photos_secure.3F_They.27re_right_there_on_my_website.21) But when I have the direct link to the picture this doesn't seem to be the case. The albums is password protected in Gallery3.

When I then type inn http://domain.not/gallery3/var/albums/folder/picturename.jpg it comes right up. This means that the direct link can be distributed without any protection after all. The Url is open too the viewer as well when holding the mouse over the pictures.

I've tried to follow this http://codex.galleryproject.org/Gallery3:FAQ#I_want_to_move_my_.2Fvar_directory to move my var directory, but it didn't work for me. I also edited the index.php file in the installer folder, but it didn't work then either.

Is there some configuration needed to be done in the .htaccess files or something, or isn't the pictures safe after all?

Gunnar.

 
floridave
floridave's picture

Joined: 2003-12-22
Posts: 27300
Posted: Sat, 2013-09-14 18:56
Quote:
The albums is password protected in Gallery3.

Did you use the password module or are you using the permissions of G3?
Permissions work just fine.

Dave
_____________________________________________
Blog & G2 || floridave - Gallery Team

 
yhagger

Joined: 2011-10-27
Posts: 4
Posted: Sat, 2013-09-14 20:21

I'm using the permissions of G3.

I figured out why I got the result I did. I was logged in as an admin. When I tried the same URL from an other browser where I wasn't logged in I got "File not found".

It works beautifully :) Sorry about the misreport of an error.