zoldos
Well-known member
So I found out that sites like "Primeyes" (not sure if it's still on-line) and other A.I. powered sites/utilities have the ability to view and maybe even index uploaded content/media on my forum without being logged on even though everything is member's only, and people must be logged in to access such things.
I tested it myself and confirmed this. Also, if someone knows the exact URL of a picture/video/zip, etc., then anyone on the web with this URL can view the content on my forum, member or not. An example is the media sharing feature in XFMG. If you give a "direct link" (from the share widget) to someone, they can then directly access the content without any account or login.
This is unacceptable for me as my site is private and adults only, and I don't allow sharing of posted content in this manner. I tried putting the entire XF folder under a domain level protected directory, which fixed it, but broke my site (lots of stuff, mainly any FA icons and moods wouldn't load, and my third party chat broke as well).
I was told I can do something with .htaccess file to prevent direct access attempts to the media/attachments folder(s). I don't know how to do this, but I did attempt a few tests that failed (I didn't get any errors, and my site still worked), but the content was still viewable without logging in.
Can anyone help? Thanks!
I tested it myself and confirmed this. Also, if someone knows the exact URL of a picture/video/zip, etc., then anyone on the web with this URL can view the content on my forum, member or not. An example is the media sharing feature in XFMG. If you give a "direct link" (from the share widget) to someone, they can then directly access the content without any account or login.
This is unacceptable for me as my site is private and adults only, and I don't allow sharing of posted content in this manner. I tried putting the entire XF folder under a domain level protected directory, which fixed it, but broke my site (lots of stuff, mainly any FA icons and moods wouldn't load, and my third party chat broke as well).
I was told I can do something with .htaccess file to prevent direct access attempts to the media/attachments folder(s). I don't know how to do this, but I did attempt a few tests that failed (I didn't get any errors, and my site still worked), but the content was still viewable without logging in.
Can anyone help? Thanks!