JohnJr

So the phpfox demo is a site which you have to sign up for.  It has a very easy to find directory/file system.

I never test this before but I was testing out out webp image will work...which I am still confused on that since even on the demo site it seems to change them to jpg files which I thought it would keep them as webp files...but that is another thread I guess.

My issue is when I uploaded that webp image to a private site that requires a sign up process and created a private group which requires an invite to view anything.  Well, I just pasted the image URL in any browser that isn't logged into the site and was able to see the image with no restrictions.  Is this right?  I guess I always assumed that phpfox code would stop anyone from opening that image but maybe I am wrong.

Don't log into the demo site and eventhough I didn't accept you into a private group you can still see this image.

https://v4.phpfox.com/PF.Base/file/pic/photo/2021/07/7717256e58361435bfb9b23104b4d5d9.jpg

being that the folder structure is always follows the pattern PF.Base/file/pic/photo/2021/07

Do all website follow this way of thinking?

 

Be the first person to like this.
Vinny

Hi John,

About your question with webp files, I belive that I already answered it in the thread " Just need verification that this is how webp works with phpfox.".

Because the link https://v4.phpfox.com/PF.Base/file/pic/photo/2021/07/7717256e58361435bfb9b23104b4d5d9.jpg has the local source PF.Base/.. so the platform doesn't cover support to check privacy right for it. That was why somebody could see the image even it belongs to private group.

Regards,

Vinny Ms.

 

Be the first person to like this.
JohnJr

My wife say I am a little deaf when I want to be..but I certainly can read so you don't have to repeat it four time...JK (Just Kidding)...LOL.  Hopefully phpfox can fix this multiple post thing that has been happening the last month or so.

Ok, I understood what you said in regards to the privacy picture of the image.  Remember someone in another thread mentioned how phpfox was letting people view their image in their S3 bucket.  But, a few weeks ago he said it was fixed.  So I assuming correctly that if I put my images on S3, and set the admin setting to not keep the images on my server.  That someone using the above URL would not be able to see the images?

Thnak you in advance for your time.

Be the first person to like this.
Vinny

Hi John,

Sorry I even didn't know I have repeated my answer 4 times :)))) I will be more careful in the next times :))))

You are correct, if you put the images on S3 and  turn off the setting "keep files in server", then the images will be viewed on S3 link but could not displayed on the server link.

Regards,

Vinny Ms.