Home · Links · Contact Us
Home arrow FAQ arrow Attachments arrow Attachments and Security
Home
Features
FAQ
Screen Shots
Modules
Demos
Documentation
Forums
Contact Us
Download
Purchase
Quotes

" ... I want to tell you that your thyme product is functional and valuable beyond words. I cannot imagine why any portal would be without it. It is the cornerstone of our new project ..."

" ... Thanks for such a complete project, its making my job much easier. ..."

" ... I have now deployed 4 different calendars and our users love them ... "

" ... Easy to install and use and a great look/design. ..."

" ... This has to be the easiest to use program I think I've had to deal with at all this year. ..."


Attachments and Security Print
Attachments
Persons who do not have access to read an event, will not have access to download that event's attachments. Even if accessing the attachment download script directly. If they try to download an attachment which they do not have permissions to view, they will be prompted to log in to Thyme.

However, the possibility exists, that someone may attempt to download an attachment directly from your webserver. For this reason, Thyme, by default, encrypts filenames in your attachments directory and uses a .dat extension. This makes it more difficult for persons to access the attachment file. Assuming you do not have any CGI program associated with .dat files, this also disallowes persons from uploading a malicious script (CGI, ASP, PHP, etc) and executing it on your web server.

If at all possible, you should move your attachments directory outside of your web server's document root. If this is not possible in your configuration, it is highly recommend that you deny all web access to your attachments directory from in web server's configuration. Consult your web server's manual for more information.

Note that Thyme places a .htaccess file in the default attachments directory which denies all web access to that directory. .htaccess files are only recognized by Apache.
 
It's all about you!
Does Thyme lack a feature you want? How may we improve it?

Buy Now
  • Secure Checkout
  • Simple, web-based installation
  • PayPal accepted

Test Drive
Download our free, 30-day trial version with no obligation to buy.

The trial download contains all the same features as the full version, so you know exactly what you're getting!

Latest Updates
© 2005 eXtrovert software unless otherwise noted. All rights reserved.
Portions © 2004 Ben Brown. All rights reserved.
Trademarks are property of their respective owners.