Gallery2 grants access without proper permission
robbt - December 27, 2006 - 12:21
| Project: | Gallery |
| Version: | 5.x-1.x-dev |
| Component: | Code |
| Category: | support request |
| Priority: | critical |
| Assigned: | Unassigned |
| Status: | closed |
Jump to:
Description
I'm trying to set-up my website so that the Gallery2 site is inaccessible unless someone logs in but the images are all still accessible to everyone. The problem I'm having is whenever I grant permission to a group it gives any anonymous user access to the listing of albums.

#1
This is a security bug, so raising to critical.
#2
I am not convinced (yet) that there is any bug here so switching to "support request".
This is unclear to me (and probably not possible with any current integration) -- what aspects of the site would be accessible/inaccessible to anonymous? Which images are you refering to which will be accessible to all (thumbnails in drupal posts via Gallery2 Filter? full size images?)? If a user has access to a full size image then they have access to your Gallery -- what is restricted here?
The permissions you are granting are via Gallery2? Permissions setting is not easy in Gallery2 and can lead to unexpected results (but is not buggy as far as I know) -- check out http://codex.gallery2.org/index.php/Gallery2:FAQ#Why_does_the_random_ima...
Can you please provide more details of the behaviour that you are requesting.
#3
No update - closing.