coppermine-gallery.com/forum

Support => cpg1.3.x Support => Older/other versions => cpg1.3 Permissions & Access Rights => Topic started by: mike12345 on August 05, 2005, 05:12:13 PM

Title: Picture Security / guess the picture path
Post by: mike12345 on August 05, 2005, 05:12:13 PM
Hi all,

Today I started to work with cpg. My first experience is good.
But now I think about the security of my pictures.
I'm planning to have albums for friends, family and everyone.
But when someone looks at the graphic properties he can see that the picture is saved in the ".../albums/userpics/" folder.

If now a person that should only see pictures for friends tries to guess other pictures names, it is possible that he can see pictures that are only for family.

And because I'm the only person, that is uploading pictures, it is not difficult to guess the names. It's always DSC0XXXX.JPG.

Is it possible to prevent that?
Is it maybe possible to save the pictures in the database? I think that should be the most secure way.

I hope everyone understand my problem. I now my English is not the best :-).


Thanks for help

Mike
Title: Re: Picture Security / guess the picture path
Post by: kegobeer on August 05, 2005, 05:30:08 PM
Binary data has no business being stored in a database, in our opinion.  We are looking into various ways to prevent people from guessing and accessing images directly.  There are several threads that talk about this.