Original showing in Lightbox - Security?

Wagon WheelWagon Wheel Registered Users Posts: 89 Big grins
edited August 30, 2013 in SmugMug Support
I just noticed, then ran several tests...
Logged IN or OUT, ANYBODY can grab the original images by simply clicking on any image in any public album, then changing the last character in the URL to "O". Is this new? Or is this trick why I do not sell any of my new photos?

BigRigTravelscom
:scratch http://www.bigrigtravels.com
Explore More of America via BigRig from
my dash mounted Live Truckcam.

Comments

  • AllenAllen Registered Users Posts: 10,013 Major grins
    edited August 30, 2013
    I just noticed, then ran several tests...
    Logged IN or OUT, ANYBODY can grab the original images by simply clicking on any image in any public album, then changing the last character in the URL to "O". Is this new? Or is this trick why I do not sell any of my new photos?

    BigRigTravelscom
    You right, it does bring up the original in lightbox.
    At first I thought is was just the X3 size but changing "X3" to "O" really makes it big.

    This is a very bad bug.

    I'll move this thread to Bugs.
    Al - Just a volunteer here having fun
    My Website index | My Blog
  • beardedgitbeardedgit Registered Users Posts: 854 Major grins
    edited August 30, 2013
    Allen wrote: »
    You right, it does bring up the original in lightbox.

    This is a very bad bug.
    I don't think it's a bug. It was like that in Legacy if you had "Show originals" enabled, and NewSM is no different. Basically, to stop it you need to change the max size that you allow to be displayed. Try X2 or X3. I would have suggested trying X4 or X5 but we ain't got them yet.
    Yippee ki-yay, footer-muckers!
  • AllenAllen Registered Users Posts: 10,013 Major grins
    edited August 30, 2013
    I have X3 as the largest size allowed in a gallery and in lightbox I can change "X3" to "O" and it opens up original.

    Checked legacy and it is still working only to allow largest size allowed in gallery settings.
    Al - Just a volunteer here having fun
    My Website index | My Blog
  • richpepprichpepp Registered Users Posts: 360 Major grins
    edited August 30, 2013
    Allen wrote: »
    You right, it does bring up the original in lightbox.
    At first I thought is was just the X3 size but changing "X3" to "O" really makes it big.

    This is a very bad bug.

    I'll move this thread to Bugs.

    I don't think it is a bug. I think if you put in O you get the largest available size but zoomed in fully. I tried it on one of my galleries which was limited to X3. If I do the O trick above then get the X3 image which I can confirm because it is both smaller than the original and watermarked. If I download the original it is much larger. Also if I right click the image to save it the image name has X3 at then end

    It might be worth temporarily disabling right click protection (if you bother to use it at all) and checking the size of the image that you get and then logging in and downloading the original to compare

    Rich
  • Wagon WheelWagon Wheel Registered Users Posts: 89 Big grins
    edited August 30, 2013
    beardedgit wrote: »
    I don't think it's a bug. It was like that in Legacy if you had "Show originals" enabled, and NewSM is no different. Basically, to stop it you need to change the max size that you allow to be displayed. Try X2 or X3. I would have suggested trying X4 or X5 but we ain't got them yet.

    NO, it shows the ORIGINAL size no matter what size is set to display. Mine is set to large max, but like mentioned, physically changing the last character to O WILL allow you to download the ORIGINAL size...
    :scratch http://www.bigrigtravels.com
    Explore More of America via BigRig from
    my dash mounted Live Truckcam.
  • beardedgitbeardedgit Registered Users Posts: 854 Major grins
    edited August 30, 2013
    Allen wrote: »
    I have X3 as the largest size allowed in a gallery and in lightbox I can change "X3" to "O" and it opens up original.

    Checked legacy and it is still working only to allow largest size allowed in gallery settings.

    Maybe this is one of those things that appears differently to different folk? I don't doubt what you say, but I'm finding it different here.

    headscratch.gif

    If I were you I'd call it in anyway, just in case.
    Yippee ki-yay, footer-muckers!
  • richpepprichpepp Registered Users Posts: 360 Major grins
    edited August 30, 2013
    Just checked another gallery. On mine the URL may say 'O' at the end but when you right click to save the image it is X3 as that is the largest I allow. However when you add the 'O' at the end you zoom right in. Maybe I have the luck of beardedgit though in not seeing the same as you are

    Rich
  • AllenAllen Registered Users Posts: 10,013 Major grins
    edited August 30, 2013
    You're right, you can only get the X3 size but why would I want anyone seeing my X3's blown up to that size?
    Al - Just a volunteer here having fun
    My Website index | My Blog
  • richpepprichpepp Registered Users Posts: 360 Major grins
    edited August 30, 2013
    why would I want anyone seeing my X3's blown up to that size?

    You don't but they can only get there if they modify the URL by hand so I'm not sure it's a problem really
  • beardedgitbeardedgit Registered Users Posts: 854 Major grins
    edited August 30, 2013
    richpepp wrote: »
    Maybe I have the luck of beardedgit though in not seeing the same as you are

    Rich
    I don't trust to luck - just because I can't get the "O" trick to see my max-X3 pics at their original size doesn't mean that everybody else can't see my X3s at "O". This NewSM's an unpredictable beast!

    If anybody wants to check for me, try the pics in http://beardedgit.smugmug.com/Everything-else/Local-Places/2009-Fireworks-in-the-Park - I've just verified that the gallery's set to show a max size of X3 and I don't see the originals if I use the "O" trick.
    Yippee ki-yay, footer-muckers!
  • richpepprichpepp Registered Users Posts: 360 Major grins
    edited August 30, 2013
    If I do the 'O' trick on your image and save it the image has a filename ending in X3 so I doubt it is the original
  • AllenAllen Registered Users Posts: 10,013 Major grins
    edited August 30, 2013
    Anyone can see the same thing by zooming their browser up to any size so it's always been able to do.

    I'll move this thread back to support because it's not a bug but others might want to discuss it.
    Al - Just a volunteer here having fun
    My Website index | My Blog
  • beardedgitbeardedgit Registered Users Posts: 854 Major grins
    edited August 30, 2013
    richpepp wrote: »
    If I do the 'O' trick on your image and save it the image has a filename ending in X3 so I doubt it is the original
    Thanks for running the check thumb.gif

    I'll reset the gallery to max="O" - I don't sell and I don't prevent copying, I allow sharing under this Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.
    Yippee ki-yay, footer-muckers!
Sign In or Register to comment.