3.Attachments

Akeeba Ticket System allows users to optionally upload attachments with their tickets and ticket replies. These files are stored on your site, in the directory you configure in the component's Options page. The default is media/com_ats/attachments.

Important

The attachments directory lives under your site's document root, and that is not something we can change. Joomla!™ requires an extension's user-uploaded files to live in a subdirectory of media named after the extension. Everything below therefore describes defence in depth around a directory which is, by default, web accessible. Please read Section3.2, “Protecting the attachments directory”.

Attachment files are stored two directory levels deep, under a mangled name. The name is the SHA-1 hash of the original filename, the current time to microsecond precision, and your site's secret key: 40 hexadecimal characters, with no file extension. The first two character pairs of that same hash form the two directory levels, e.g. media/com_ats/attachments/1f/3a/1f3a….

This is a best-effort mitigation, and it is worth being precise about what it does and does not achieve. The names are drawn sparsely from an enormous search space, so an unauthorised user cannot realistically guess or brute-force one; and because the files have no extension, a correctly configured web server will not execute them as code. What it is not is access control: anyone who obtains the URL by some other means can fetch the file. It is obscurity — useful, deliberate, and not a substitute for actually denying access to the directory.

Akeeba Ticket System ships two files into the attachments directory to deny direct web access: a .htaccess file, which works on most — but not all — Apache™ and LiteSpeed installations, and a web.config file, which works on most IIS™ installations. Whether either takes effect depends on your server's configuration; on Apache, for example, .htaccess files are ignored entirely unless the server is set up to allow overrides. There is no equivalent file for NginX: NginX has no per-directory configuration mechanism at all, so we cannot ship anything that protects the directory there.

Attachments have, by default, the same visibility as the ticket itself. Therefore, attachments in public tickets are visible to everyone and can be downloaded by anyone who has their URL. You can optionally make all attachments private. This means that attachments in public tickets will only be visible to and can be downloaded by the person submitting the ticket they belong to and users with the Support Staff permission.

Akeeba Ticket System has its own set of upload permissions; it does not use the same ones used by the Media Manager. This is intentional. The Media Manager is set up to allow the upload of files which need to be publicly accessible on your site, mostly images, videos, audio files, PDFs, and office application files. Attachments in a ticket system tend to be archives, log files, even executables depending on the nature of the support you are offering through the ticket system. Therefore it makes sense to have a different set of upload permissions to allow for files of a different nature to be uploaded. You can find these settings in the component's Options page.

3.1.Which files can be uploaded

The checks applied to uploaded attachments are set in the Attachments tab of the component's Options page. Akeeba Ticket System hands them to Joomla's own upload checks, the same code the Media Manager uses, with the option values you set. This section explains what the default values allow, and how to tighten them if your support process does not need that.

3.1.1.What the defaults allow, and why

The default values are chosen for support desks, where clients routinely need to send log files, archives, installers, scripts, and configuration files. With the default values, once the component's Options have been saved:

  • The file name must still be safe (no path separators or other special characters) and must have an extension. Files larger than the Maximum size are rejected.

  • Allowed executable extensions lists every extension Joomla considers executable (exe, msi, bat, js, jar, py, php, phar, html, htm, and so on). Joomla's check which rejects a file with an executable extension anywhere in its name, such as invoice.php.pdf, is therefore effectively turned off.

  • Ignored Extensions for MIME Type checks contains the same list of executable extensions. It is only displayed when Check MIME Types is enabled, but its value is saved and used regardless. Joomla accepts a file if its last extension is in either Allowed extensions or this list, and files matched by this list skip the MIME type check. In practice this means executables, scripts, and HTML files (setup.exe, fix.bat, debug.php, page.html) are accepted, in addition to everything in Allowed extensions.

  • Check MIME Types is disabled, so files in Allowed extensions are accepted without checking that their content matches their extension, as long as a MIME type can be detected at all.

This does not put your server at risk. Attachments are stored under a random name without an extension (see Section3, “Attachments”), so a web server will not execute them, and Akeeba Ticket System always sends them to the browser as a download. The risk is to the people who download and open attachments: a client, or someone impersonating a client, can send your support staff an executable or an HTML file through a channel they trust. Make sure your staff treat attachments with the same care as email attachments.

3.1.2.A stricter configuration

If your clients do not need to send executables, scripts, or HTML files, we recommend the following settings in the Attachments tab of the component's Options page:

  1. Unsafe uploads: No.

  2. Restrict Uploads: Yes.

  3. Allowed executable extensions: empty. This restores Joomla's check for executable extensions anywhere in the file name.

  4. Allowed extensions: only the extensions you actually expect, for example jpg,jpeg,png,gif,webp,pdf,txt,log,csv,zip,7z. Remember that this list is case-sensitive.

  5. Check MIME Types: Yes.

  6. Ignored Extensions for MIME Type checks: empty. Note that you must first set Check MIME Types to Yes to see and clear this field; clearing it matters even if you later set Check MIME Types back to No.

  7. Legal MIME Types: the MIME types matching your Allowed extensions. The MIME type is detected from the file's content by PHP, and it is not always the one you may expect. For example, ZIP archives are usually detected as application/zip, which is not in the default list (the default list has application/x-zip); modern Office documents are detected as application/vnd.openxmlformats-officedocument.wordprocessingml.document and similar; and CSV or log files may be detected as text/csv or text/plain. Test uploading one file of each type you allow after changing this option.

With this configuration the following will be rejected, with an error message shown to the person uploading the file:

  • Any file with an executable extension anywhere in its name, whatever its last extension: for example setup.exe, fix.bat, script.js, app.jar, tool.py, index.php, page.html, but also invoice.php.pdf and photo.exe.jpg.

  • Any file whose last extension is not in Allowed extensions, for example install.sh, config.ini, drawing.svg, or backup.jpa if you did not list those extensions.

  • Any file whose content does not match a Legal MIME Type, even if its extension is allowed. This catches, for example, an executable renamed to report.pdf, an HTML page renamed to notes.txt (detected as text/html), or a file whose type PHP cannot detect at all. It will also reject legitimate files whose detected type you did not list, which is why testing is important.

Clients who need to send you a file type you have excluded can still put it inside a ZIP archive, provided you allow ZIP archives. Akeeba Ticket System does not look inside archives.