Topic Title: Search Box - Security

Forum Index » Gallery 1 Integration » Search Box - Security
Topic URL: http://www.nukedgallery.net/postt105.html

AuthorMessage
Post Title: Search Box - Security
rkd
Joined: Aug 06, 2003
Posts: 2
Location: Seattle, WA
Posted: Wed Aug 06, 2003 1:12 am
Love Photo Gallery!

I have a family gallery that is password protected and I found a problem. On the main login page the user name and password box pops up ok, but anyone can type a single letter into the search box and hit enter and your into the gallery. I would like to know if there is a way to correct this? I went into the script and removed the search box, but it removed it from all the pages. I would like to see it only gone from the login page, and usable on the other pages. Any suggestions how to fix or do this? Idea

Thanks,
Robb
----
Give us your Gallery/webserver information to get a faster answer.
Get this information from the PHP diagnostic (in the configuration wizard).
Gallery URL (optional but very useful): http://digital-photos.us
Gallery version: 1.3.5-cvs-b53
Apache version: 1.3.28
PHP version (don't just say PHP 4, please): 4.3.2
Graphics Toolkit:
Operating system: xp
Web browser/version (if applicable): ie 6.0

AuthorMessage
Post Title:
slackbladder
Joined: Mar 29, 2003
Posts: 1038
Location: Cambs,UK
Posted: Wed Aug 06, 2003 1:27 am
Hi,

Why are you password protecting the gallery/albums?

Did you try using the PERMISSION system?

EXAMPLE:
set to LOGGEDIN to access photos - so users have to register first
or
set to NOBODY - then you (as admin) will have to manually move the users name into the 'WHO CAN VIEW' list after they have registered as a member.

AuthorMessage
Post Title:
dari
Joined: Mar 03, 2003
Posts: 6287
Location: Washington Township, NJ, USA
Posted: Wed Aug 06, 2003 7:23 am
this is the best way of doing it, since with upgrades, your code changes may be lost.

AuthorMessage
Post Title: Re: Search Box - Security
rkd
Joined: Aug 06, 2003
Posts: 2
Location: Seattle, WA
Posted: Wed Aug 06, 2003 10:42 pm
Yes, I know about the permission box. I have set my gallery to LOGGEDIN. Go to my webpage gallery and you will see no albums. Type the letter P in the Search Box and you will see my protected Albums...

http://www.digital-photos.us/modules.php?name=gallery


Let me know if I explained the problem better.


Robb

AuthorMessage
Post Title:
slackbladder
Joined: Mar 29, 2003
Posts: 1038
Location: Cambs,UK
Posted: Thu Aug 07, 2003 1:26 am
Confused Hmn - thats strange!

Try setting the gallery module and block to REGISTERED users only from nuke admin. It looks like you don't want anyone to see ANY of the pix without being logged in - so that would be the easiest way.

AuthorMessage
Post Title:
dari
Joined: Mar 03, 2003
Posts: 6287
Location: Washington Township, NJ, USA
Posted: Thu Aug 07, 2003 7:25 am
wow. this is a pretty serious issue. i am going to reference this thread in the gallery forums for the developers to take a look at.

All times are GMT - 5 Hours
Powered by PHPNuke and phpBB2 © 2006 phpBB Group