Results 1 to 6 of 6
  1. #1
    Join Date
    Aug 2006
    Posts
    6
    Plugin Contributions
    0

    Default why i can download file from download folder directly?

    the .htaccess file may not be taking effect.
    my host is linux.why?
    Thank you.

  2. #2
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: why i can download file from download folder directly?

    Sounds like your host is not allowing the .htaccess settings work with your site to protect your directories ...

    Who are you hosting with and what do you have in the .htaccess file on the server in the /download directory?
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today: v1.5.5]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  3. #3
    Join Date
    May 2006
    Posts
    89
    Plugin Contributions
    0

    Default Re: why i can download file from download folder directly?

    I have the same problem.

    Should the .htaccess file allow a specific user? Or does it have to be a particular user that the zen-cart knows about?

    Or would the zen-cart care?

    I am concern that if I protect the directory, then none of my downlaods will work.

    Thanks!

    Norma

  4. #4
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: why i can download file from download folder directly?

    HappyMom,

    If your cart is running on Linux (not Windows) and you have Download-by-redirect enabled or download-by-streaming enabled, then the .htaccess only needs simple protection ... to block everyone.
    Zen Cart will read the files there via direct access, bypassing the .htaccess restrictions. Once it reads the files, it can make them available to download via the methods I just mentioned.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    May 2006
    Posts
    89
    Plugin Contributions
    0

    Default Re: why i can download file from download folder directly?

    Thanks DrByte!

    Just for further clarification...

    Where is the "Download-by-redirect enabled" or "download-by-streaming enabled" flag?

    Is it on the zen-cart? or php? or the site?

    Thanks a lot for your support!

    Norma

  6. #6
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: why i can download file from download folder directly?

    Quote Originally Posted by HappyMom View Post
    Where is the "Download-by-redirect enabled" or "download-by-streaming enabled" flag?
    Admin->Configuration->Attribute Settings
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. Can we customize the DOWNLOAD Folder ?
    By prabhatM in forum Setting Up Categories, Products, Attributes
    Replies: 5
    Last Post: 6 Jul 2015, 06:58 PM
  2. v151 download folder doesn't exist - can it be recreated?
    By suedouglas in forum General Questions
    Replies: 9
    Last Post: 28 Mar 2015, 03:03 PM
  3. COWOA won't allow customer to download file from download folder
    By fawad123 in forum All Other Contributions/Addons
    Replies: 0
    Last Post: 18 May 2011, 01:27 PM
  4. download folder - .htaccess file
    By mipavluk in forum General Questions
    Replies: 6
    Last Post: 10 Feb 2009, 03:05 AM
  5. Adding file extensions to .htaccess in download folder
    By ingoito in forum General Questions
    Replies: 0
    Last Post: 28 Jan 2009, 09:11 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR