dcblogdev / dcblogcomments

2 stars 0 forks source link

securing-elfinder-with-a-login-page #42

Open utterances-bot opened 2 years ago

utterances-bot commented 2 years ago

Securing elFinder with a login page - DC Blog

elFinder is a great file manager, it can integrate easily into many web editors, Its installation...

https://dcblog.dev/securing-elfinder-with-a-login-page

ghost commented 2 years ago

Many thanks. Worked out very well. Enjoy your day!

paulmer commented 2 years ago

Is anything protecting the connector URL? Seems like a user could guess it and issue calls directly, bypassing the web form all together. It's not sufficient to merely require a password to view the form, the API needs access control as well.