# Setting/Ability to Require account to download files

**URL:** <https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686>\
**Category:** Feature\
**Created:** [2014年九月5日 15:47 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686 "2014-09-05T15:47:01Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Schleicher](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eric_schleicher/32/114801_2.png) [@Eric\_Schleicher](https://meta.discourse.org/u/Eric_Schleicher)\
**Post date:** [2014年九月5日 15:47 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/1 "2014-09-05T15:47:02Z")

</div>

We have an instance we we would like anonymous public traffic to freely view/browse the forums, but restrict the ability to download files to people who have accounts (required logged in). I looked through the settings and didn’t see anything alluding to such a capability. This is pretty common configuration/behavior for other forum solutions. wasn’t sure whether there is a philosophical driver for not having this type of functionality, or it just hasn’t come up yet.

Eric

+1 for this feature.

---

<div class="post-metadata">

**Author:** ![eviltrout](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eviltrout/32/5275_2.png) [@eviltrout](https://meta.discourse.org/u/eviltrout)\
**Post date:** [2014年九月5日 15:51 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/2 "2014-09-05T15:51:08Z")

</div>

I don’t think there’s a philosophical reason to do this; we just implemented the easiest case first.

@zogstrip how hard would it be to add a site setting to prevent anons from downloading files?

---

<div class="post-metadata">

**Author:** ![mcwumbly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcwumbly/32/103861_2.png) [@mcwumbly](https://meta.discourse.org/u/mcwumbly)\
**Post date:** [2014年九月5日 15:55 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/3 "2014-09-05T15:55:43Z")

</div>

We ended up creating a separate private sub-category for downloads.

That works well for us, but perhaps isn’t the best fit for everyone.

---

<div class="post-metadata">

**Author:** ![lake54](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lake54/32/121955_2.png) [@lake54](https://meta.discourse.org/u/lake54)\
**Post date:** [2014年九月5日 17:47 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/4 "2014-09-05T17:47:43Z")

</div>

I’ve popped this in as a bug about a month ago, although it probably fits better as a feature request.

> [@Attachments available to any user with link](https://meta.discourse.org/t/attachments-available-to-any-user-with-link/18868):
>
> Repro Create a restricted category, and post an attachment in there. With another account, one that doesn’t have access to the restricted category, try and access the uploaded file (e.g. the original user has copied the link, perhaps in a forwarded email by mistake) User is able to access the file This is more a people issue rather than a technical one I think, since instead of sharing the link, they could just email the attachment themselves anyway. If there is, however, any way of validatin…

---

<div class="post-metadata">

**Author:** ![Eric\_Schleicher](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eric_schleicher/32/114801_2.png) [@Eric\_Schleicher](https://meta.discourse.org/u/Eric_Schleicher)\
**Post date:** [2014年九月5日 21:11 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/5 "2014-09-05T21:11:24Z")

</div>

So in this use case, on’y authorized (which presumes authenticated) people can see topics for that sub category? did i get that right.

---

<div class="post-metadata">

**Author:** ![mcwumbly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcwumbly/32/103861_2.png) [@mcwumbly](https://meta.discourse.org/u/mcwumbly)\
**Post date:** [2014年九月5日 21:15 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/6 "2014-09-05T21:15:59Z")

</div>

yeah, authenticated users are trust\_level\_0.

We have it set like so:

 ![](https://global.discourse-cdn.com/meta/original/3X/f/8/f838e713789c4592b18deae1382329efa174af48.PNG)

---

<div class="post-metadata">

**Author:** ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)\
**Post date:** [2014年九月5日 21:22 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/7 "2014-09-05T21:22:26Z")

</div>

> [@mcwumbly](#):
>
> We ended up creating a separate private sub-category for downloads.

Yes, but as @lake54 wrote in [Attachments available to any user with link](https://meta.discourse.org/t/attachments-available-to-any-user-with-link/18868) those attachments are still accessible to people with the URL. So not foolproof in terms of limiting access to attachments.

FWIW, I am not especially enamored with forums that block access to content until you sign in and use teasers to get people to sign up. I guess I just don’t like to be teased. The private members-only goodies just never seem to be as good as I hope they would be.

---

<div class="post-metadata">

**Author:** ![mcwumbly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mcwumbly/32/103861_2.png) [@mcwumbly](https://meta.discourse.org/u/mcwumbly)\
**Post date:** [2014年九月5日 21:28 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/8 "2014-09-05T21:28:30Z")

</div>

Agreed. Our use case is pretty specific and it happens to work fine for us, but YMMV.

---

<div class="post-metadata">

**Author:** ![zogstrip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zogstrip/32/512781_2.png) [@zogstrip](https://meta.discourse.org/u/zogstrip)\
**Post date:** [2014年九月9日 16:41 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/9 "2014-09-09T16:41:25Z")

</div>

> [@eviltrout](#):
>
> @zogstrip how hard would it be to add a site setting to prevent anons from downloading files?

Not very hard 😉

[https://github.com/discourse/discourse/commit/eb34ecfc0c2133ee977801774a5721d453b64443](https://github.com/discourse/discourse/commit/eb34ecfc0c2133ee977801774a5721d453b64443)

---

<div class="post-metadata">

**Author:** ![elberet](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elberet/32/122404_2.png) [@elberet](https://meta.discourse.org/u/elberet)\
**Post date:** [2014年九月9日 17:29 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/10 "2014-09-09T17:29:50Z")

</div>

Did you test this with an uploaded file that actually existed in the test environment? In my development environment, `thin` serves existing files in `public/uploads/` without going through Rails, and I would imagine that most nginx’s and unicorns in production will behave the same way…

Also, this breaks the recommended way of customizing Discourse’s design by posting design assets as attachments in a staff thread; and any images embedded in posts render as broken/missing without an explanation or error message.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [2014年九月9日 22:32 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/11 "2014-09-09T22:32:58Z")

</div>

@zogstrip the site setting should mention this risk. I’ll try to edit it in.

> Prevent anonymous users from downloading files. WARNING: this will prevent any site assets posted as attachments from working.

---

<div class="post-metadata">

**Author:** ![zogstrip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zogstrip/32/512781_2.png) [@zogstrip](https://meta.discourse.org/u/zogstrip)\
**Post date:** [2014年九月10日 16:41 UTC](https://meta.discourse.org/t/setting-ability-to-require-account-to-download-files/19686/12 "2014-09-10T16:41:45Z")

</div>

This topic was automatically closed after 24 hours. New replies are no longer allowed.
