diff options
author | Craig Andrews <candrews@integralblue.com> | 2010-01-05 17:47:37 -0500 |
---|---|---|
committer | Craig Andrews <candrews@integralblue.com> | 2010-01-05 17:49:28 -0500 |
commit | 250bcfa8dc3ebf3c2c8458f363a62c529eb3a7f6 (patch) | |
tree | 4fd0fb9272a06f38bc3ba7a9522015b92fdd224f /README | |
parent | 7e01bb8d4f9036a7e1638aa7ba325f7660b5b086 (diff) |
Require users to login to view attachments on private sites
Thank you jeff-themovie for this implementation!
Diffstat (limited to 'README')
-rw-r--r-- | README | 20 |
1 files changed, 15 insertions, 5 deletions
@@ -710,11 +710,21 @@ private site, but users of the private site may be able to subscribe to users on a remote site. (Or not... it's not well tested.) The "proper behaviour" hasn't been defined here, so handle with care. -If fancy URLs is enabled, access to file attachments can also be -restricted to logged-in users only. Uncomment the appropriate rewrite -rule in .htaccess or your server's httpd.conf. (This most likely will -not work if you are using a virtual server for attachments, so consider -the performance/security tradeoff.) +Access to file attachments can also be restricted to logged-in users only. +1. Add a directory outside the web root where your file uploads will be + stored. Usually a command like this will work: + + mkdir /var/www/mublog-files + +2. Make the file uploads directory writeable by the web server. An + insecure way to do this is: + + chmod a+x /var/www/mublog-files + +3. Tell StatusNet to use this directory for file uploads. Add a line + like this to your config.php: + + $config['attachments']['dir'] = '/var/www/mublog-files'; Upgrading ========= |