Advertisement:

Author Topic: Big Performance Tip: Specify a Custom Avatar Directory  (Read 118679 times)

Offline aED

  • Sr. Member
  • ****
  • Posts: 980
  • Gender: Male
    • Free internet UBT/FBT - Opera Mini
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #20 on: March 28, 2009, 03:09:34 AM »
Is this applicable to SMF RC1?

Offline 青山 素子

  • Server Team
  • SMF Super Hero
  • *
  • Posts: 17,072
  • 戦場ヶ原、蕩れ!
    • srvrguy on GitHub
    • @motokochan on Twitter
    • Nekomusume Moe
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #21 on: March 28, 2009, 07:47:58 PM »
2.0 RC1?

It should be.
Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.


Offline akguide

  • Semi-Newbie
  • *
  • Posts: 24
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #22 on: April 19, 2009, 03:23:47 PM »
I created the folder on my server as avs  gave it the same permissions as the attachments folder, however I get An Error Has Occurred!
The attachments upload directory is not writable. Your attachment or avatar cannot be saved.
when trying to upload an image from profile

oh and if I get that figured out how do I run the script to have database look for the images in the new location?

Thanks in advance.

Offline TigPT

  • Semi-Newbie
  • *
  • Posts: 29
  • Gender: Male
    • Tiago Rodrigues
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #23 on: May 28, 2009, 01:34:28 PM »
I have just lost my avatars on my server after run the sql query, and when i do this code:


index.php?action=manageattachments;sa=moveAvatars

i get the error:
O directório de upload dos anexos não é de escrita. O seu anexo ou avatar não pode ser gravado.
(can't write, don't have premissions)
Even with the avs path with same acess as atachments one.

Can someone help me? Thanks.

Offline Something like that

  • SMF Friend
  • SMF Hero
  • *
  • Posts: 2,496
  • Gender: Male
  • ]
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #24 on: September 12, 2009, 10:42:06 AM »
I have just lost my avatars on my server after run the sql query, and when i do this code:


index.php?action=manageattachments;sa=moveAvatars

i get the error:
O directório de upload dos anexos não é de escrita. O seu anexo ou avatar não pode ser gravado.
(can't write, don't have premissions)
Even with the avs path with same acess as atachments one.

Can someone help me? Thanks.

If the permissions match, chances are you typed in the path to the directory incorrectly.

Offline Romanj

  • Semi-Newbie
  • *
  • Posts: 12
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #25 on: December 15, 2009, 12:56:30 PM »
What about security of this way access to avatars?
As I know, when user upload his file on site, and then place and name of this file on server is known, its security vulnerability.
Or there are no reasons to worry about it?


p.s. sorry for my broken english:)

Offline Arantor

  • Resident Overthinker
  • SMF Friend
  • SMF Legend
  • *
  • Posts: 71,863
    • StoryBB/StoryBB on GitHub
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #26 on: December 15, 2009, 01:08:47 PM »
It's only an issue if the file contains something malicious. SMF has protection against it.

Note this very forum uses this method.
Don’t try to tell me that some power can corrupt a person. You haven’t had enough to know what it’s like.

No good deed goes unpunished / No act of charity goes unresented.

Offline Tanshaydar

  • Jr. Member
  • **
  • Posts: 178
  • Gender: Male
  • manifestations of delusions
    • Kişisel
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #27 on: December 18, 2009, 03:40:29 PM »
There is a problem for me, when I choose Upload Avatars -> "to a specific directory" I can't enter a directory. I'm using 2.0 RC2

Offline Arantor

  • Resident Overthinker
  • SMF Friend
  • SMF Legend
  • *
  • Posts: 71,863
    • StoryBB/StoryBB on GitHub
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #28 on: December 18, 2009, 03:47:50 PM »
That's a reported bug in 2.0 RC2, I think.
Don’t try to tell me that some power can corrupt a person. You haven’t had enough to know what it’s like.

No good deed goes unpunished / No act of charity goes unresented.

Offline Tanshaydar

  • Jr. Member
  • **
  • Posts: 178
  • Gender: Male
  • manifestations of delusions
    • Kişisel
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #29 on: December 18, 2009, 03:57:52 PM »
Oh, I see.
Thanks.

Offline Something like that

  • SMF Friend
  • SMF Hero
  • *
  • Posts: 2,496
  • Gender: Male
  • ]
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #30 on: December 18, 2009, 04:43:09 PM »
What about security of this way access to avatars?
As I know, when user upload his file on site, and then place and name of this file on server is known, its security vulnerability.
Or there are no reasons to worry about it?


p.s. sorry for my broken english:)

It's just an image.

There is a small potential for a security vulnerability, if you have other vulnerable software running on the same machine, but not with SMF.

Offline NoobDeveloper

  • Jr. Member
  • **
  • Posts: 331
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #31 on: December 19, 2009, 03:36:43 AM »
hi All

Nice tip.  But i have one doubt.  After i create a separate directory in root folder what should be its permission set ? 777 or 775 or any other ?

Please guide me.  Thanks in advance.

Note :  I am on shared hosting and don't want any security issues after this change.

Offline Owdy

  • SMF Fossil
  • SMF Friend
  • SMF Super Hero
  • *
  • Posts: 15,627
  • Gender: Male
  • W00t!
    • janoloferiksson on LinkedIn
    • @@jaoler on Twitter
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #32 on: December 19, 2009, 05:00:49 AM »
777 is fine
Former Lead Support Specialist

Tarvitsetko apua SMF foorumisi kanssa? Otan työtehtäviä vastaan, lue:http://www.simplemachines.org/community/index.php?topic=375918.0

Offline NoobDeveloper

  • Jr. Member
  • **
  • Posts: 331
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #33 on: December 19, 2009, 05:02:03 AM »
777 is fine

then what about security ? Any compromise on that ?

Offline Owdy

  • SMF Fossil
  • SMF Friend
  • SMF Super Hero
  • *
  • Posts: 15,627
  • Gender: Male
  • W00t!
    • janoloferiksson on LinkedIn
    • @@jaoler on Twitter
Former Lead Support Specialist

Tarvitsetko apua SMF foorumisi kanssa? Otan työtehtäviä vastaan, lue:http://www.simplemachines.org/community/index.php?topic=375918.0

Offline Arantor

  • Resident Overthinker
  • SMF Friend
  • SMF Legend
  • *
  • Posts: 71,863
    • StoryBB/StoryBB on GitHub
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #35 on: December 19, 2009, 05:19:52 AM »
777 is only a security risk if you are on a shared server. Anything where you're the only user generally isn't.
Don’t try to tell me that some power can corrupt a person. You haven’t had enough to know what it’s like.

No good deed goes unpunished / No act of charity goes unresented.

Offline NoobDeveloper

  • Jr. Member
  • **
  • Posts: 331
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #36 on: December 19, 2009, 05:26:00 AM »
777 is only a security risk if you are on a shared server. Anything where you're the only user generally isn't.

thanks. Yes i am on a shared host. And have already moved the location of folder where avatars are stored.  now please tell me what to do ? what permission should i set to that folder ?

also see if you can help me here
http://www.simplemachines.org/community/index.php?topic=354763.0

Offline Arantor

  • Resident Overthinker
  • SMF Friend
  • SMF Legend
  • *
  • Posts: 71,863
    • StoryBB/StoryBB on GitHub
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #37 on: December 19, 2009, 05:50:12 AM »
On a shared host, 775 or better 755.
Don’t try to tell me that some power can corrupt a person. You haven’t had enough to know what it’s like.

No good deed goes unpunished / No act of charity goes unresented.

Offline NoobDeveloper

  • Jr. Member
  • **
  • Posts: 331
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #38 on: December 19, 2009, 05:55:09 AM »
ok i will set it to 755 for my new avatar directory.

also my Public_html folder is set to 777.

what should i set it to ? 

Offline Arantor

  • Resident Overthinker
  • SMF Friend
  • SMF Legend
  • *
  • Posts: 71,863
    • StoryBB/StoryBB on GitHub
Re: Big Performance Tip: Specify a Custom Avatar Directory
« Reply #39 on: December 19, 2009, 06:03:55 AM »
755 generally, however note that it may have consequences for you for updates as so on depending on how the host set it up.
Don’t try to tell me that some power can corrupt a person. You haven’t had enough to know what it’s like.

No good deed goes unpunished / No act of charity goes unresented.