I'm trying to set-up my website so that the Gallery2 site is inaccessible unless someone logs in but the images are all still accessible to everyone. The problem I'm having is whenever I grant permission to a group it gives any anonymous user access to the listing of albums.

Comments

Aren Cambre’s picture

Priority: Normal » Critical

This is a security bug, so raising to critical.

kiz_0987’s picture

Category: bug » support

I am not convinced (yet) that there is any bug here so switching to "support request".

I'm trying to set-up my website so that the Gallery2 site is inaccessible unless someone logs in but the images are all still accessible to everyone.

This is unclear to me (and probably not possible with any current integration) -- what aspects of the site would be accessible/inaccessible to anonymous? Which images are you refering to which will be accessible to all (thumbnails in drupal posts via Gallery2 Filter? full size images?)? If a user has access to a full size image then they have access to your Gallery -- what is restricted here?

The problem I'm having is whenever I grant permission to a group it gives any anonymous user access to the listing of albums.

The permissions you are granting are via Gallery2? Permissions setting is not easy in Gallery2 and can lead to unexpected results (but is not buggy as far as I know) -- check out http://codex.gallery2.org/index.php/Gallery2:FAQ#Why_does_the_random_ima...

Can you please provide more details of the behaviour that you are requesting.

kiz_0987’s picture

Status: Active » Closed (fixed)

No update - closing.