Keyword

How Secure are K2 Attachments?

  • Manuel Kuhs
  • Manuel Kuhs's Avatar Topic Author
  • Offline
  • New Member
More
11 years 5 months ago #112563 by Manuel Kuhs
How Secure are K2 Attachments? was created by Manuel Kuhs
If I create a K2 Item and set its access level to Registered or even stricter, and I attach a file to this item, how secure is the attachment? Will Google index the attachment? Can an unregistered user download the attachment if they are given the direct link to it?

Please Log in or Create an account to join the conversation.

  • Manuel Kuhs
  • Manuel Kuhs's Avatar Topic Author
  • Offline
  • New Member
More
11 years 5 months ago - 11 years 5 months ago #112564 by Manuel Kuhs
Replied by Manuel Kuhs on topic Re: How Secure are K2 Attachments?
Well I was playing around with it and it does NOT seem secure at all.

I created an item and added an attachment. I copied the URL to the attachment. I then set the item to Registered users. Now when I try to load the item, it correctly requires me to sign in. HOWEVER if I directly access the URL to the attachment, I am able to download the attachment without signing in!!

Please Log in or Create an account to join the conversation.

  • Mohamed Abdelaziz
  • Mohamed Abdelaziz's Avatar
  • Offline
  • Platinum Member
  • Joomla Developer
More
11 years 5 months ago #112565 by Mohamed Abdelaziz
Replied by Mohamed Abdelaziz on topic Re: How Secure are K2 Attachments?
If you plan to restrict the access of attachments to a specific user type, then you need to think about using document manager such as DOCman or jDownloads for example.

Multiple Extra Fields Groups for K2
AutoMeta for K2
Chained Fields for K2
More K2 Extensions In My Extensions Store

Please Log in or Create an account to join the conversation.


Powered by Kunena Forum