I'm using a masked control panel and have CKFinder security problems.
I am using MSM with WYGWAM 2.1.2 and I have EE setup to use masked control panels. I was wondering if there is any way to work around CKFinders file upload security issues because of the different domain name my control panel is masked with.
-
Hi Jason,
Masked CPs are fine, since Wygwam 2.x stores all of its front-end files in your themes folder, not your system folder.
Only thing is, your themes folder has to be on the same domain that you're accessing your CP from, for javascript security reasons that you're running into.
Go into your General Configuration prefs, and set your "URL to your 'themes' folder" to a root-relative URL (e.g. "/themes/") rather than one that includes the whole domain. Then, either copy the entire contents of the folder, or create a symlink on your secondary domain. So, http://site1.com/themes/ is mirrored on http://site2.com/themes/.
Does that make sense? -
-
Thanks. I feel a little slow that I didn't think that through myself. That should work out great.
-
Loading Profile...


Twitter,
Facebook, or email.

EMPLOYEE
