6.0.0-git
2019-03-23

[#9178] guest photo download fails
Summary guest photo download fails
Queue Ansel
Queue Version 1.1.1
Type Bug
State Resolved
Priority 1. Low
Owners
Requester mmartin (at) mnet-online (dot) de
Created 2010-08-16 (3141 days ago)
Due
Updated 2010-09-11 (3115 days ago)
Assigned 2010-08-16 (3141 days ago)
Resolved 2010-09-10 (3116 days ago)
Milestone
Patch Yes

History
2010-09-11 07:02:45 mmartin (at) mnet-online (dot) de Comment #8 Reply to this comment
I guess this can be closed then?
ok, thx
2010-09-10 16:58:51 Michael Rubinsky State ⇒ Resolved
 
2010-09-10 15:34:50 Jan Schneider Comment #7 Reply to this comment
I guess this can be closed then?
2010-08-17 14:50:10 Michael Rubinsky Comment #6 Reply to this comment
i think this is already there, in the gallery settings, You have the setting
'Who should be able to download (original) photos':
- everybody
- logged in users
- users with read permissions
(backtranslated from german :-)
i thought the permission check in download checks then this setting
This determines if a user can download the original image file (the 
full-size file that was originally uploaded) instead of the resized 
image that is used in the image view. This is different then allowing 
zip downloads. Creating, and then transferring, a zip file that could 
conceivably contain *every* image in the gallery is not a good thing 
to allow the world to do.

2010-08-17 07:43:20 mmartin (at) mnet-online (dot) de Comment #5 Reply to this comment
The idea is to prevent downloading of zip files by guests in order 
to prevent potential DOS attacks. Generating and downloading the zip 
files is very resource intensive, and for large galleries, having 
the world be able to do this is probably not a Good Idea.

I'd be willing to make this an additional permission on Ansel, so it 
has to be explicitly allowed. "Allow guests to download zip files" 
or something similar.
i think this is already there, in the gallery settings, You have the setting
'Who should be able to download (original) photos':
- everybody
- logged in users
- users with read permissions
(backtranslated from german :-)
i thought the permission check in download checks then this setting




2010-08-16 18:07:38 Git Commit Comment #4 Reply to this comment
2010-08-16 18:03:48 CVS Commit Comment #3 Reply to this comment
2010-08-16 17:57:34 Michael Rubinsky Comment #2
State ⇒ Feedback
Reply to this comment
The idea is to prevent downloading of zip files by guests in order to 
prevent potential DOS attacks. Generating and downloading the zip 
files is very resource intensive, and for large galleries, having the 
world be able to do this is probably not a Good Idea.

I'd be willing to make this an additional permission on Ansel, so it 
has to be explicitly allowed. "Allow guests to download zip files" or 
something similar.
2010-08-16 12:53:22 mmartin (at) mnet-online (dot) de Comment #1
Type ⇒ Bug
State ⇒ Unconfirmed
Priority ⇒ 1. Low
Summary ⇒ guest photo download fails
Queue ⇒ Ansel
Milestone ⇒
Patch ⇒ Yes
Reply to this comment
when trying to download a gallery or selected Photos as a zip file,
the Access denied message appears when You are not logged in (guest),
even when guests have read permission.

the attached patch corrects that by removing the superfluous
!Auth::getAuth()
from image.php and gallery.php

Saved Queries