Zen Cart Logo
Forums / All Other Contributions/Addons / ckeditor - does it upload images

ckeditor - does it upload images

Views: 11,775

Results 1 to 20 of 35
14 May 2010, 4:14 AM
#1
kachana avatar

kachana

New Zenner

Join Date:
Oct 2008
Posts:
24
Plugin Contributions:
0

ckeditor - does it upload images

Does CKEDITOR allow you to upload images to your server?

Thanks

14 May 2010, 5:31 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: ckeditor - does it upload images

Not natively, no.

14 May 2010, 12:37 PM
#3
kachana avatar

kachana

New Zenner

Join Date:
Oct 2008
Posts:
24
Plugin Contributions:
0

Re: ckeditor - does it upload images

Thank you for that prompt rely:)

3 Jun 2010, 4:32 AM
#4
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

There is a CKFinder file manager, but haven't had luck integrating with CKEditor...:blink:

3 Jun 2010, 7:41 AM
#5
kuroi avatar

kuroi

Totally Zenned

Join Date:
Apr 2006
Location:
London, UK
Posts:
10,475
Plugin Contributions:
11

Re: ckeditor - does it upload images

It's not easy to integrate Image Manager extensions to WYSIWYG editors such as CKEditor or TinyMCE.

If you don't integrate them securely, you leave yourself open to the upload of malicious files by hackers.

But integrating them securely is very difficult too as Zen Cart is deliberately locked down to not offer third-party apps a way to penetrate its security, since these would offer a point of attack for hackers.

3 Jun 2010, 2:45 PM
#6
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

Hi kuroi,

First, I would like to say thanks for the contrib! As you read in my other post, It installed and works flawlessly, including the upgrade process. CKEditor is a nice addition for Zen users.

I do understand the potential security issues with file managers. However, if one does wish to configure CKFinder, would you happen to have any helpful directions on this? :smile:

3 Jun 2010, 8:07 PM
#7
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

OK, got ckfinder working on localhost!

Now I am trying to secure it. In the ckfinder config.php file, there is a CheckAuthentication() function that needs to return true. I added the following, but doesn't seem to work. :blink:

 return isset($_SESSION['securityToken']) && $_SESSION['securityToken'];

This should return true if admin is logged in...correct?

Any ideas?

3 Jun 2010, 8:37 PM
#8
kuroi avatar

kuroi

Totally Zenned

Join Date:
Apr 2006
Location:
London, UK
Posts:
10,475
Plugin Contributions:
11

Re: ckeditor - does it upload images

Alas that won't work as the page has already been completely rendered by the time you initiate the CKFinder call, and the session has been closed down to protect the information that it contains.

Nor can you restart the same session at this point, since the http headers were sent prior to the page rendering.

If you're working from a fixed IP you might be able to check that the browser request came from that IP and exclude any others.

You can also obscure the location of the editors (similarly to changing the name of the admin folder) by renaming the folder and editing the DIR_WS_EDITOR setting in the admin ckeditor.php file, which would make it more difficult for a hacker to find and access the CKFinder upload facility.

3 Jun 2010, 9:49 PM
#9
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

Thanks for the info about Zen sessions kuroi.

I had tried several methods, but as you pointed out, Zen sessions by design, are very secure...

I like the idea of obscuring the dir and looking at the IP...

Would there be any other way to validate that one is logged in to the store admin that can be made available to the ckfinder config script?

3 Jun 2010, 10:27 PM
#10
kuroi avatar

kuroi

Totally Zenned

Join Date:
Apr 2006
Location:
London, UK
Posts:
10,475
Plugin Contributions:
11

Re: ckeditor - does it upload images

Alas, the information used to verify that somebody is logged in is in the session that you can't get at.

4 Jun 2010, 1:42 AM
#11
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

Got it!

So, other then the suggested IP restriction and editors dir name change, any other validation suggestion one could do to verify that ckfinder is not being hacked?

Also, my ckeditor.php file doesn't have a DIR_WS_EDITOR setting. I guess I need to code this?

Thanks again! :clap:

28 Jun 2010, 9:47 AM
#12
terragirl avatar

terragirl

Zen Follower

Join Date:
Jun 2010
Location:
Austria
Posts:
123
Plugin Contributions:
0

Re: ckeditor - does it upload images

I stumbled across this thread when I had to secure CKFinder in Zen Cart. The IP address restriction didn't work for me, as my client is on a variable IP.

So I slapped a cPanel folder protection on and this should do the trick. It asks for the log in as soon as you access a page in admin which has CKFinder embeded and also if you try to access CKFinder directly.

Maybe this helps others who come across this thread.

All the best, Edith

28 Jun 2010, 5:56 PM
#13
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

OK, don't mean to beat a horse as they say...

I have CKEditor and CKFinder installed and working on 1.3.9d. I want to secure (as best as possible) CKFinder.

Here's what I have so far in general:

  1. Admin dir renamed
  2. htaccess pwd admin dir
  3. Using https to login
  4. limited file types in finder to gif, jpg and png

I read in another thread to pwd the editor and finder dir as well. Any thought on this redundancy?

Since I don't know the methods a hacker could use to get in and use CKFinder, any other suggestions / recommendation (other then don't use CKFinder) would be helpful to all of us that need / wish to use CKFinder.

Thanks :D

18 Jul 2010, 4:46 PM
#14
vandiermen avatar

vandiermen

Totally Zenned

Join Date:
Feb 2007
Posts:
518
Plugin Contributions:
1

Re: ckeditor - does it upload images

kwright:

I want to secure (as best as possible) CKFinder.

I had FCKeditor(with image uploader) installed on all my 1.3.8 sites and just changed the admin url, and I was never hacked.

If you change your admin url this should protect your site.

I looked for CKFinder in the free ad-ons... pity no one has added it for zencart.

p.s.
without changing the admin url your site is vulnerable I think.

18 Jul 2010, 4:49 PM
#15
kuroi avatar

kuroi

Totally Zenned

Join Date:
Apr 2006
Location:
London, UK
Posts:
10,475
Plugin Contributions:
11

Re: ckeditor - does it upload images

vandiermen:

I looked for CKFinder in the free ad-ons... pity no one has added it for zencart.It can't be added for Zen Cart. It's a commercial product requiring a paid-for license.

18 Jul 2010, 5:01 PM
#16
vandiermen avatar

vandiermen

Totally Zenned

Join Date:
Feb 2007
Posts:
518
Plugin Contributions:
1

Re: ckeditor - does it upload images

kuroi:

It can't be added for Zen Cart. It's a commercial product requiring a paid-for license.

It seems you can download it for free for your own websites. Perhaps zencart integration patch files could be added I am not sure. Thanks for your answer.

18 Jul 2010, 5:06 PM
#17
vandiermen avatar

vandiermen

Totally Zenned

Join Date:
Feb 2007
Posts:
518
Plugin Contributions:
1

Re: ckeditor - does it upload images

p.s.
if you got some reseller licence from CKSource, and sold the module for zencart on your website; I would buy it. :-)

19 Jul 2010, 10:38 PM
#18
kwright avatar

kwright

Zen Follower

Join Date:
Nov 2004
Posts:
355
Plugin Contributions:
0

Re: ckeditor - does it upload images

vandiermen:

I had FCKeditor(with image uploader) installed on all my 1.3.8 sites and just changed the admin url, and I was never hacked.

If you change your admin url this should protect your site.

I looked for CKFinder in the free ad-ons... pity no one has added it for zencart.

p.s.
without changing the admin url your site is vulnerable I think.

Yup, done that! Even changed the editor & CKFinder dir name...I just feel there is something else I should do that would better authenticate if an admin user is "Logged-in" within the CKFinder config.php CheckAuthentication function :flex:

20 Jul 2010, 8:38 AM
#19
kuroi avatar

kuroi

Totally Zenned

Join Date:
Apr 2006
Location:
London, UK
Posts:
10,475
Plugin Contributions:
11

Re: ckeditor - does it upload images

@vandierman The CKFinder people don't offer a reseller license. They have an OEM license, but it's not compatible with the GPL under which Zen Cart is released.

@kwright I believe that this can be done, but would require relocating the entire editor structure into the Admin to gain access to the admin session.

3 Aug 2010, 4:14 AM
#20
tonyniemann avatar

tonyniemann

New Zenner

Join Date:
May 2010
Location:
Rocky Mountains, Colorado USA
Posts:
5
Plugin Contributions:
0

Re: ckeditor - does it upload images

Don't know if anyone cares anymore but here is the solution I came up with for CKFinder security. Basically it limits access to the IP address of the logged in admin - it's not perfect but it's pretty good.

I establish the access to CKFinder in #admin#/includes/ckeditor.php but I'm sure this idea could be ported.

In ckeditor.php I added the following:

if (!defined('IS_ADMIN_FLAG')) {
  die('Illegal Access');
}

/* BEGIN ADD */
$IP = $HTTP_SERVER_VARS["HTTP_X_FORWARDED_FOR"]; 
$currentcode =  md5('salt_one' . $IP . 'salt_two');
/* END ADD */

$var = zen_get_languages();

The "salt_one" and "salt_two" are hardcoded random strings.

Then I added the access lines to the CKEDITOR.replace call like so

      CKEDITOR.replace($(this).attr('name'),
        {
          coreStyles_underline : { element : 'u' },
          width : 760,
          language: lang[index],
          filebrowserBrowseUrl: '../<?php echo DIR_WS_EDITORS ?>ckfinder/ckfinder.html?lcsd=<?php echo $currentcode ?>',
          filebrowserImageBrowseUrl: '../<?php echo DIR_WS_EDITORS ?>ckfinder/ckfinder.html?type=Images&lcsd=<?php echo $currentcode ?>',
          filebrowserUploadUrl: 
            '../<?php echo DIR_WS_EDITORS ?>ckfinder/core/connector/php/connector.php?command=QuickUpload&type=Files&lcsd=<?php echo $currentcode ?>',
          filebrowserImageUploadUrl: 
            '../<?php echo DIR_WS_EDITORS ?>ckfinder/core/connector/php/connector.php?command=QuickUpload&type=Images&lcsd=<?php echo $currentcode ?>'
        });

Now I have a parameter being passed to the CKFinder that is unique to the current users IP address (proxies, etc notwithstanding).

Then, over in the /ckfinder/config.php I test for this new parameter:

function CheckAuthentication()
{
    $IP = $HTTP_SERVER_VARS["HTTP_X_FORWARDED_FOR"];     
    $currentcode =  md5('salt_one' . $IP . 'salt_two');
    $testcode = '';
    
    if (isset($_REQUEST['lcsd'])) {
        $testcode = $_REQUEST['lcsd'];
    };

    return ($testcode == $currentcode);    
}

Perhaps I'm missing something obvious, but so far it appears to be working.

Tony