Viewing 10 posts - 1 through 10 (of 10 total)
Eli

Downloadable Products not protected

Hello everyone! I have made a download test for some products and it seems that they are not protected,anyone how have the url can download the products freely because the urls are not encrypted... How do i protect them...?

Created: November 15, 2014 at 1:32 am

  • cat
    cat
    November 15, 2014 at 4:41 am

    you had best make this issue known to support Eli
    thats a huge problem that needs a fix urgently
    thanks for letting us all know though.

  • cat
    cat
    November 15, 2014 at 5:03 am

    Just a thought, though I dont use the digital downloads theme, Im assuming that the uploads are going straight to the uploads folder
    open the uploads folder, go through to each folder, eg: 2014>11 and all etc and in each one add a blank index.html page
    that way no-one can get into the folder
    unfortunately if they know what the product is called they can just type the url and still get it.
    See if there is a way that you can put your products inside a zip folder with a CODE name like a-338
    so example, if your product is an ebook about fishing, you could put that zip inside a zip named a-fish-443392
    Then on an info page on your site (FAQ) write something like “how do I access my product?” and your answer: For security reasons mysite.com places all digital files inside a package zip with a name like: z-neon-331. You will need to extract this zip.

    Problem with this is that if you do have some unscrupulous person buy a product, they will just post the link and name of the product on some website somewhere and tell all their friends where to get it.
    Meaning that you will need to monitor your cpanel and see how many times that url has been accessed (using the same zip name)
    and then change the “exterior” zip name when required.
    At least until pp makes the download folder unfindable…
    or makes uploaded products folder change its name every time a product is sold (individual download link) and only allows a buyer to download x amount of times for x amount of hours after purchase before the link deletes.
    Or sends the product by email in a zip so that there never is a link to see or use or give to friends or post on another website for freebies.


  • Eli
    November 28, 2014 at 10:36 am

    Hello Cat!
    Thank you for your reply…
    Downloadable product site must work automatically in my opinion.
    I used to work with “Easy Digital Download” plugin which encodes the Download link and limits the amount of downloads after purchase.
    I’ll let you know when I find an automatic solution to this.
    Anyway Thank you!

  • Legibus Maximus
    Legibus Maximus
    December 2, 2014 at 10:45 am

    This is no bueno! I just installed this today and thought I’d check to see if I had the same problem. Anyone can just download it once they know the url of the file. Have you put in a ticket for this yet? That needs to be corrected asap. I noticed when I download the child theme it’s different than the actual file name. The download url defaults to the url of the directory url https://www.premiumpress.com/childthemes/?oldtheme=business-directory/ and even if i add the file name, template_businessdirectory.zip, to the end of that url I get a page not found redirect. How can I set this up on my site the same way?

  • Legibus Maximus
    Legibus Maximus
    December 2, 2014 at 10:57 am

    Let me know if you figure this out.

  • cat
    cat
    December 21, 2014 at 12:05 am

    Has this been fixed in new updates for december 4-2014?


  • Alexander
    January 9, 2015 at 12:38 pm

    Please: thats a huge problem that needs a fix urgently

  • Mark Fail
    Mark Fail
    February 28, 2015 at 8:34 am

    You should upload your product files to below your www or public_html folder and then use the path to the file in your download setting.

    If you upload files to a public area then obviously they are publicly accessible.


  • Eli
    April 19, 2015 at 10:00 am

    Thank you Mike!
    I did as you have specified here and the problem was solved.
    Now no one can download the files unless he have a user account on the site.
    Many thanks!

Copyright © 2010-2020 PremiumPress Limited.

secure payments