rejetto forum

Software => HFS ~ HTTP File Server => Bug reports => Topic started by: rubberbutt on March 25, 2021, 07:37:34 PM

Title: user account login
Post by: rubberbutt on March 25, 2021, 07:37:34 PM
Hello all.

I have a question about the user accounts. Or lack off

I use HFS 2,3. I forwarded port 8080 to my pc in my router. I don't have a domain name yet, but I can reach my HFS through my external wan ip address.
Everyone can see the "homepage"of HFS. So everyone sees the files and can download them.
I haven't even made a user account.
Is this normal behaviour from  HFS ? So why bother even making user accounts ?
Title: Re: user account login
Post by: Mars on March 25, 2021, 09:40:23 PM
this behavior is completely normal, everything is accessible as long as no protection policy is in place,

unless you really want to share sensitive data with the rest of the world, it is unconscious to open an external port without having first set up a minimum of security

start by creating a personal user account and protecting each element of the VFS tree structure,

depending on the listening port used or all of them, you can test the web content using the address 127.0.0.1 in the browser on the pc, or its ip address on the local network,

to connect to the internet address, it is necessary to use another provider

these links do not reflect all the possibilities and latest version of hfs, but it can help to start your server

http://rejetto.com/wiki/index.php?title=First_time_configuration

http://rejetto.com/forum/index.php?topic=1939.0
Title: Re: user account login
Post by: rubberbutt on March 26, 2021, 06:23:32 AM
Ah ok.  It's not that i have sensitive data, but i have this data on my own home Windows server.
I have a limited data usage per month. I just don't want everyone to "pull"data of my server.

So i want to restrict to known persons, friends etc.
So what i want is that every user (no matter who it is) HAS to login. So users may only see the home hfs page after they have logged in. Is this possible ?

Title: Re: user account login
Post by: danny on March 26, 2021, 08:53:30 AM
So what i want is that every user (no matter who it is) HAS to login.
Virtual File System
🏠/
right-click
properties
access tab, put checkbox in 'can change password' (a user-group)
OK/Apply.   
Verify that a padlock icon shows at /
Save virtual file system (saves your changes)

After that, go to menu/other/user, and add some users to the group 'can change password' to allow access
Title: Re: user account login
Post by: regchan on April 13, 2021, 10:54:40 PM
i actually have  my file layout is   
i secure the login section to force the login
and i have a simple webpage as the root directory



url/login/private files


each line is the hierachy
/----myhtml.html
/-----Login -- folder has padlock on it to make user login
/---login-------- > your private files mormally red icon folder