Support » Plugin: Sunshine Photo Cart » Images still viewable with direct link

  • Resolved bellsandy

    (@bellsandy)


    Hi there,

    I have been testing out the Pro functionality and I am seeing issues with image security, which I think is also applicable to the free plugin.

    Images are still accessible when the gallery is set to ask for an email address or even password protected. The only option that doesn’t allow image viewing is the user account, but I don’t want anyone to be able to register or see the images if they have a direct link for some reason. Downloads thankfully do not seem to work on the direct links without passwords.

    Also anyone can add a comment if you click on the download button from the unprotected lightbox. Pre-registering clients seems like the only work around…can we track favorites with just the email address?

    Having a Sunshine/company themed log in page might work better, then it wouldn’t be blatantly obvious we are using wordpress and have clients get confused that they got lost. Having a user role Sunshine Client might be cool, too.

    • This topic was modified 8 months ago by bellsandy.
    • This topic was modified 8 months ago by bellsandy.
    • This topic was modified 8 months ago by bellsandy.
Viewing 7 replies - 1 through 7 (of 7 total)
  • Plugin Author sunshinephotocart

    (@sunshinephotocart)

    I could not confirm any issues when a gallery requires a password, going directly to an image does still prompt for the gallery password. I did confirm the bug where going directly to an image when you want an email address it would show the image without having to enter an email – this is fixed and will be in the next release.

    If you want to hide the default WordPress login look, there are 3rd party login plugins you can use to customize the look and feel of it.

    bellsandy

    (@bellsandy)

    I still can see an individual photo even when it is password protected. I have password protected AND provide email address selected in the gallery settings. Maybe that makes a difference?

    Plugin Author sunshinephotocart

    (@sunshinephotocart)

    I cannot reproduce a situation where a password protected gallery allows access to the images without a password. I recommend checking in an incognito window or separate browser to confirm you haven’t already entered the password for that gallery. The other situation was confirmed and fixed for the next release though.

    Well then I’m not sure what I’m doing wrong, but I open a private window in Firefox and I can see this link without entering a password: http://sandrastrandphotography.com/client-galleries/gallery/schneider-family#401 . If I close the lightbox the password protected message is behind it, but I can still access that link above and page through the whole gallery. A new inPrivate window in Edge does the same thing.

    • This reply was modified 7 months, 3 weeks ago by bellsandy.
    Plugin Author sunshinephotocart

    (@sunshinephotocart)

    OK, that is with the Lightbox enabled. These forums are for the free version which does not include the Lightbox. This is why providing an actual URL is so vital to help figure out the issue. I will look into the issue in regards to the Lightbox and password galleries

    Plugin Author sunshinephotocart

    (@sunshinephotocart)

    The lightbox add-on has been updated to fix this issue.

    Thanks! Glad it’s sorted. Will send an email next time I have a pro feature question.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Images still viewable with direct link’ is closed to new replies.