Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Password circumvention by directly accessing 'galleries' URI #58

Open
hb9eue opened this issue Feb 9, 2025 · 0 comments
Open

Password circumvention by directly accessing 'galleries' URI #58

hb9eue opened this issue Feb 9, 2025 · 0 comments

Comments

@hb9eue
Copy link

hb9eue commented Feb 9, 2025

Hi

I just installed novagallery. Thank you for that nice and easy to use gallery.

I have some galleries I rather don't want to make accessible publicly, unfortunately it is not yet possible to set access control to single galleries. So I set the password hash for the entire gallery.

That does not prevent anyone who guesses the /galleries/ URI to still browse and access the images and even the cached thumbnails.

Adding:

Options all -Indexes

to the main .htaccess mitigates the issue.

-Benoît-

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant