Can you hide the download link url?

Phoca Download - download manager
arathra
Phoca Member
Phoca Member
Posts: 10
Joined: 04 Aug 2008, 14:51

Can you hide the download link url?

Post by arathra »

Quite simply, is there a way to cloak the download link with a random string so that it can't be edited to get files which a user isn't entitled to?

Something like changing this:

http://DOMAIN/index.php?option=com_phoc ... download=1

to this:

http://DOMAIN/index.php?option=com_phoc ... dsa893hd89

That is, generate a random string for the file which only lasts for the duration of the stay so that it can't be edited to take another file.

(NB all users are registered here, they just have different statuses within that category.)
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49144
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Can you hide the download link url?

Post by Jan »

Hi, sorry I don't understand - in the URL there is no name of the file and you need to identificate it somehow :idea:
If you find Phoca extensions useful, please support the project
arathra
Phoca Member
Phoca Member
Posts: 10
Joined: 04 Aug 2008, 14:51

Re: Can you hide the download link url?

Post by arathra »

Jan wrote:Hi, sorry I don't understand - in the URL there is no name of the file and you need to identificate it somehow :idea:
No, but there's a number. It doesn't take a lot of guesswork to change that in the URL and download a different file.
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49144
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Can you hide the download link url?

Post by Jan »

but how will the script identify that the added key is the right - if there will be no ID and the key should be changed?
If you find Phoca extensions useful, please support the project
arathra
Phoca Member
Phoca Member
Posts: 10
Joined: 04 Aug 2008, 14:51

Re: Can you hide the download link url?

Post by arathra »

I found an extension which does this: http://extensions.joomla.org/extensions ... oads/10717

It disguises the URL so that people can't try to guess the download string for another file.
Post Reply