fckeditor是一个非常好用的网页在线编辑器,但是其配置往往会出现一些问题,比如在上传时提示“this connector is disabled Please check the"editor/filemanager/connectors/aspx/config.aspx”。很多人会手足无措,因为找不到config.aspx文件,只有一个config.ascx文件。

在config.ascx文件中有一个方法如下:

/**
* This function must check the user session to be sure that he/she is
* authorized to upload and access files in the File Browser.
*/
private bool CheckAuthentication()
{
// WARNING : DO NOT simply return "true". By doing so, you are allowing
// "anyone" to upload and list the files in your server. You must implement
// some kind of session validation here. Even something very simple as...
//
// return ( Session[ "IsAuthorized" ] != null && (bool)Session[ "IsAuthorized" ] == true );
//
// ... where Session[ "IsAuthorized" ] is set to "true" as soon as the
// user logs in your system. return false;
}

细心的朋友会详细的读一下该部分的英文注释:不要简单的将返回结果改为true,因为这个方法是检查用户身份的,如果简单的改为true,则上传文件将不受任何限制。