kreativostudio
01-13-2010, 09:18 PM
I have installed the subscription plugin and assigned to paid categories, but the big problem is that files are exposed and able to download to anyone, here the details:
When you are not a "Paid member" you can't donwload attachments, nor if someone give you de the direct link to download, you get a blank page http://www.yoursite.com/admindir/download.php?force&file=files/downloads/yourfile_541946463.jpg
But... if someone is smart enough, that person can trim the url and get the direct link to download attachments without paying a penny http://www.yoursite.com/files/downloads/yourfile_541946463.jpg
So the million question is "HOW TO PROTECT FILES IN ORDER TO AVOID THIS PROBLEM" :confused:
I hope someone understand this and test it in its own server to get what I mean.
When you are not a "Paid member" you can't donwload attachments, nor if someone give you de the direct link to download, you get a blank page http://www.yoursite.com/admindir/download.php?force&file=files/downloads/yourfile_541946463.jpg
But... if someone is smart enough, that person can trim the url and get the direct link to download attachments without paying a penny http://www.yoursite.com/files/downloads/yourfile_541946463.jpg
So the million question is "HOW TO PROTECT FILES IN ORDER TO AVOID THIS PROBLEM" :confused:
I hope someone understand this and test it in its own server to get what I mean.