Forums

Group Documents
[resolved] Authenticate before download (2 posts)

  1. sanderbontje
    Member
    Posted 7 months ago #

    First of all, thanks for all your work! This plugin would really suit our needs for handling documents in our community's site. But one small thing is keeping us from using it: the way documents are unprotected.

    I've created new public, private and hidden groups and uploaded documents to all of them.
    The link to any document (although somewhat obfuscated) can be used by any user to get access to that document. All he needs to do is guess the correct url. There is no need to log in to proof group membership.

    I know a question similar to this came up earlier, but that topic has been closed. Any news on the subject?

    Thanks :)

    http://wordpress.org/extend/plugins/buddypress-group-documents/

  2. sanderbontje
    Member
    Posted 4 months ago #

    This code on the link below was just what I needed. It allows the group-documents folder that you use to store your files to be be placed outside your DocumentRoot. It adds an extra security layer that filters the requests throught BP and checks whether the visitor is logged in and has access to the file.

    http://dev.commons.gc.cuny.edu/2011/02/05/hardening-buddypress-group-documents/

    Task "User verification for Downloads" from roadmap.txt completed. :)

Reply

You must log in to post.

About this Plugin

About this Topic