[dokuwiki] Re: somewhat urgent question - hiding contents in _media

  • From: Andreas Gohr <andi@xxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Sun, 23 Mar 2008 22:21:28 +0100

On Sun, 23 Mar 2008 19:06:58 +0000
Christopher Smith <chris@xxxxxxxxxxxxx> wrote:

> 
> On 23 Mar 2008, at 14:54, Tobias Eigen wrote:
> > Hi Andi,
> >
> > It is now possible for unauthenticated people to access all the
> > contents of the _media path, including google. This is disastrous
> > for us as we have been using the wiki for internal discussions and
> > planning. We have namespaces set up to be public, and others set up
> > to be private. All content uploaded to the wiki, whatever the
> > namespace, is publicly visible.

What Chris said is probably the answer to your real question hower
there is something in you post not matching your Chris' answer...

You're talking about _media - _media is a rewrite pointing to
fetch.php. fetch.php will honor your ACLs when delivering files, so
there are two things to check:

- are links in google pointing to _media or to data/media ?
- When it is the former, your ACLs are probably not set up correctly.
Remember only namespace ACLs are relevant for media files. When it is
the latter see what Chris said.

Andi

-- 
http://www.splitbrain.org

Other related posts: