File Download Without Authorization

0 views
Skip to first unread message

Phil

unread,
Feb 5, 2010, 3:02:18 AM2/5/10
to In-Portal Bugs Team
Hello,

on 502, english install on Wamp server, I've tested the Download
product type.

Once order approved, the download is available in "My Downloads", as
expected, and the download link is
http://website.tld/products/in-commerce/elements/download.elm/test.html?env=file.downl---

I've been very surprised to discover that this download link works
anytime, on any other browser, even after I logged out.
How does filtering on download permissions applies? Does this problem
belong to my local installation?

I haven't been able to test it on a 502 yet, but I'll let you know
asap.

Phil.

Dmitry A.

unread,
Feb 8, 2010, 1:23:23 PM2/8/10
to In-Portal Bugs Team
Hi Phil,


Did you have a chance to test this on 5.0.2 just yet?


Thanks.

On Feb 5, 2:02 am, Phil <p...@domicilis.biz> wrote:
> Hello,
>
> on 502, english install on Wamp server, I've tested the Download
> product type.
>
> Once order approved, the download is available in "My Downloads", as

> expected, and the download link ishttp://website.tld/products/in-commerce/elements/download.elm/test.ht...

Alexander Obuhovich

unread,
Feb 8, 2010, 1:37:51 PM2/8/10
to in-port...@googlegroups.com
As you can see in Phil original post it's already in 5.0.2 installation in Wamp server.

--
You received this message because you are subscribed to the Google Groups "In-Portal Bugs Team" group.
To post to this group, send email to in-port...@googlegroups.com.
To unsubscribe from this group, send email to in-portal-bug...@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/in-portal-bugs?hl=en.




--
Best Regards,

http://www.in-portal.com
http://www.alex-time.com

Alexander Obuhovich

unread,
Mar 14, 2010, 4:31:27 PM3/14/10
to in-port...@googlegroups.com
I've tested on 5.0.3 version and when I have no permission to download products file and I visit file download link (obtained from user, who has right to download that file), then I get "File Access permission check failed!" message and no file is sent to user.

Here is the link I've used: "http://www.site.com/products/sub-products/in-commerce/elements/download.elm/download-me.html?env=file.downl---" (on "advanced" theme).

If you are talking about direct link to file from "/system/downloads" folder, then you should check, that ".htaccess" from that folder is read by webserver configuration.

If you are talking about ability to be able to directly

Dmitry Andrejev

unread,
Mar 25, 2010, 2:43:15 AM3/25/10
to in-port...@googlegroups.com
Hi Phil,

You should check this on 5.0.3 on your end and update this discussion.

DA.

Phil ..:: domicilis.biz ::..

unread,
Mar 25, 2010, 5:23:29 AM3/25/10
to in-port...@googlegroups.com
Hi Dmitry,

I've planned to check on this later this week or beginning of next one.

P.

2010/3/25 Dmitry Andrejev <dand...@gmail.com>:

Reply all
Reply to author
Forward
0 new messages