• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Wordpress hotlink protection not working with domain alias

levilsdarum

New Pleskian
TITLE:
Wordpress hotlink protection not working with domain alias
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE:
CentOS Linux 7.6.1810 / Plesk Onyx v17.8.11 / Wordpress 5.2.3
PROBLEM DESCRIPTION:
When enabling the hotlink protection, using the WordPress Toolkit, images can't be loaded through aliased domains, only the subscription is allowed to view the images.​
STEPS TO REPRODUCE:
Create subscription/domain a.com, install WordPress, upload an image (in a page, for example). In the media gallery on a.com/wp-admin, the image will be visible.

Then create a domain-alias, for example b.com. Go to b.com/wp-admin, go to the media gallery, same image(s) will be visible.

Now, use the WordPress Toolkit to enable hotlink protection on the installed WordPress on a.com.​
ACTUAL RESULT:
When opening the media gallery a.com/wp-admin, the images are still there.

When opening the media gallery on b.com/wp-admin (the same site, just an alias), all images will be replaces by an images showing 'This image was hotlinked'.

image.png
EXPECTED RESULT:
When hotlink protection is enabled, is should be possible to view images on the subscription / main domain, as well as on it's configured domain-aliases.​
ANY ADDITIONAL INFORMATION:
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM:
Confirm bug
 
Thank you for the report!
Here is developer's reply:

I created the bug: EXTWPTOOLK-3533.
At the moment hotlink protection allows access only through main domain name, and disallow any aliases.
 
Back
Top