Jump to content

Xenboy

Clients
  • Posts

    217
  • Joined

  • Last visited

Reputation Activity

  1. Agree
    Xenboy got a reaction from Linux-Is-Best in Secure File System Storage   
    And also take a large hit in performance, plus, storing multi-GB files in a database isn't recommended, but is something the file system can handle.
  2. Agree
    Xenboy got a reaction from CoffeeCake in Secure File System Storage   
    In a number of popular web scripts like Drupal, the software has the ability to specify a non-public location for the software to store and serve files from. IPS doesn't allow this, you can only specify file system locations that are within the web root of the account (meaning that there is direct access to the files via a URL). For security, best practice is to store data outside of your web root location. This stops people from uploading files and then accessing them via direct URL and potentially compromising the account or even the server (particularly on servers where the web server does not run PHP scripts as the local user). 
    It would be nice if IPS supported local file system access outside of web root. Right now, IPS also allows you to specify a local file system storage location outside of the web root, but if you use that file storage location, those items will no longer be accessible by IPS once the system moves them. If nothing else, IPS should warn people in the ACP that if you specify a file system location outside of the web root, the items won't be accessible.
  3. Like
    Xenboy got a reaction from SJ77 in Additional Commerce Payment Method - Square   
    It's probably not specifically about the feature set for most people, I'd guess. It's about allowing those of us with an existing Square merchant account to use it here as well. Having to use two different merchants is a serious pain and can be somewhat expensive for those who have paid for infrastructure with Square.
    Both Square and Stripe are popular with small business and having both would make IPS Commerce more useful out of the box. 
  4. Like
    Xenboy got a reaction from Numbered in Secure File System Storage   
    In a number of popular web scripts like Drupal, the software has the ability to specify a non-public location for the software to store and serve files from. IPS doesn't allow this, you can only specify file system locations that are within the web root of the account (meaning that there is direct access to the files via a URL). For security, best practice is to store data outside of your web root location. This stops people from uploading files and then accessing them via direct URL and potentially compromising the account or even the server (particularly on servers where the web server does not run PHP scripts as the local user). 
    It would be nice if IPS supported local file system access outside of web root. Right now, IPS also allows you to specify a local file system storage location outside of the web root, but if you use that file storage location, those items will no longer be accessible by IPS once the system moves them. If nothing else, IPS should warn people in the ACP that if you specify a file system location outside of the web root, the items won't be accessible.
  5. Like
    Xenboy got a reaction from Cyboman in Secure File System Storage   
    In a number of popular web scripts like Drupal, the software has the ability to specify a non-public location for the software to store and serve files from. IPS doesn't allow this, you can only specify file system locations that are within the web root of the account (meaning that there is direct access to the files via a URL). For security, best practice is to store data outside of your web root location. This stops people from uploading files and then accessing them via direct URL and potentially compromising the account or even the server (particularly on servers where the web server does not run PHP scripts as the local user). 
    It would be nice if IPS supported local file system access outside of web root. Right now, IPS also allows you to specify a local file system storage location outside of the web root, but if you use that file storage location, those items will no longer be accessible by IPS once the system moves them. If nothing else, IPS should warn people in the ACP that if you specify a file system location outside of the web root, the items won't be accessible.
×
×
  • Create New...