Only admin can upload files


First post! I was hoping I could get through Elgg without having to make one! 

I've spent a good 5hrs this evening trying to get to grips with restricting File uploads to Admins only. I managed to find the "Gatekeeper" workaround for creating pages, but I'm not having any joy with the files. 

I need the facility to be able to stop users uploading files of any description and for this facility just to be made available to the admin. I'm not too fussed about it looking pretty and removing the upload / zip boxes - I just need to stop them from actually doing it. 

Hope somebody can take the time to help me, My Elgg installation depends on this and I've come so far, this is my last issue before I can go live. 

Thanks in advance, 


  • quikNderty = mod\file\actions\file\upload.php


  • And you can use the function elgg_is_admin_logged_in() to check if the user is an admin

  • ;-oO Matt.. we're 1/2 the time crossing tee hee.. hope (aint dozed & that) he realizesi merely gave really Quick N Dirty Solution - not *the proper way ! Sounded 2 2 deperate;P soo..

  • Hi

    I'm afraid I'm still having no joy with this. Not sure If I've misunderstood what I need to do. 

    I tried adding a admin_gatekeeper() line into the upload.php but this stopped me from uploading any files, even when logged in as the administrator. 

    Do you reckon you could spot me a step by step for me to follow to stop standard users from uploading files. Apologies - not a coder. 



  • nope ;-) the answers are all above ;-P
    but if you wanna post here :-
    * exact fully qualified name of the php script file you are editing and
    * the exact code that's causing you grief..

    someone cud probably spot the problems quickish

    ++ What version of Elgg ?


  • Hi, don't know what you mean by "fully qualifed" but

    I'm editing

    xx\mod\file\actions\file\upload.php, as below - using 

    Release - 1.8.8, Version - 2012071100

    * Elgg file uploader/edit action
    * @package ElggFile

    // Get variables
    $title = get_input("title");
    $desc = get_input("description");
    $access_id = (int) get_input("access_id");
    $container_guid = (int) get_input('container_guid', 0);
    $guid = (int) get_input('file_guid');
    $tags = get_input("tags");

    if ($container_guid == 0) {
    $container_guid = elgg_get_logged_in_user_guid();


    // check if upload failed
    if (!empty($_FILES['upload']['name']) && $_FILES['upload']['error'] != 0) {

    // check whether this is a new file or an edit
    $new_file = true;
    if ($guid > 0) {
    $new_file = false;

    if ($new_file) {
    // must have a file if a new file upload
    if (empty($_FILES['upload']['name'])) {
    $error = elgg_echo('file:nofile');

    $file = new FilePluginFile();
    $file->subtype = "file";

    // if no title on new upload, grab filename
    if (empty($title)) {
    $title = $_FILES['upload']['name'];

    } else {
    // load original file object
    $file = new FilePluginFile($guid);
    if (!$file) {

    // user must be able to edit file
    if (!$file->canEdit()) {

    if (!$title) {
    // user blanked title, but we need one
    $title = $file->title;

    $file->title = $title;
    $file->description = $desc;
    $file->access_id = $access_id;
    $file->container_guid = $container_guid;

    $tags = explode(",", $tags);
    $file->tags = $tags;

    // we have a file upload, so process it
    if (isset($_FILES['upload']['name']) && !empty($_FILES['upload']['name'])) {

    $prefix = "file/";

    // if previous file, delete it
    if ($new_file == false) {
    $filename = $file->getFilenameOnFilestore();
    if (file_exists($filename)) {

    // use same filename on the disk - ensures thumbnails are overwritten
    $filestorename = $file->getFilename();
    $filestorename = elgg_substr($filestorename, elgg_strlen($prefix));
    } else {
    $filestorename = elgg_strtolower(time().$_FILES['upload']['name']);

    $file->setFilename($prefix . $filestorename);
    $mime_type = ElggFile::detectMimeType($_FILES['upload']['tmp_name'], $_FILES['upload']['type']);

    // hack for Microsoft zipped formats
    $info = pathinfo($_FILES['upload']['name']);
    $office_formats = array('docx', 'xlsx', 'pptx');
    if ($mime_type == "application/zip" && in_array($info['extension'], $office_formats)) {
    switch ($info['extension']) {
    case 'docx':
    $mime_type = "application/vnd.openxmlformats-officedocument.wordprocessingml.document";
    case 'xlsx':
    $mime_type = "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet";
    case 'pptx':
    $mime_type = "application/vnd.openxmlformats-officedocument.presentationml.presentation";

    // check for bad ppt detection
    if ($mime_type == "application/" && $info['extension'] == "ppt") {
    $mime_type = "application/";

    $file->originalfilename = $_FILES['upload']['name'];
    $file->simpletype = file_get_simple_type($mime_type);

    // Open the file to guarantee the directory exists
    move_uploaded_file($_FILES['upload']['tmp_name'], $file->getFilenameOnFilestore());

    $guid = $file->save();

    // if image, we need to create thumbnails (this should be moved into a function)
    if ($guid && $file->simpletype == "image") {
    $file->icontime = time();

    $thumbnail = get_resized_image_from_existing_file($file->getFilenameOnFilestore(), 60, 60, true);
    if ($thumbnail) {
    $thumb = new ElggFile();


    $file->thumbnail = $prefix."thumb".$filestorename;

    $thumbsmall = get_resized_image_from_existing_file($file->getFilenameOnFilestore(), 153, 153, true);
    if ($thumbsmall) {
    $file->smallthumb = $prefix."smallthumb".$filestorename;

    $thumblarge = get_resized_image_from_existing_file($file->getFilenameOnFilestore(), 600, 600, false);
    if ($thumblarge) {
    $file->largethumb = $prefix."largethumb".$filestorename;
    } else {
    // not saving a file but still need to save the entity to push attributes to database

    // file saved so clear sticky form

    // handle results differently for new files and file updates
    if ($new_file) {
    if ($guid) {
    $message = elgg_echo("file:saved");
    add_to_river('river/object/file/create', 'create', elgg_get_logged_in_user_guid(), $file->guid);
    } else {
    // failed to save file object - nothing we can do about this
    $error = elgg_echo("file:uploadfailed");

    $container = get_entity($container_guid);
    if (elgg_instanceof($container, 'group')) {
    } else {

    } else {
    if ($guid) {
    } else {


  • yew did post the qualified filename ;-P
    you did not post the badd code !;(
    anyways - if you change this file to

        * Elgg file uploader/edit action
        * @package ElggFile
        // Get variables

    should block any non-Admin from executing a file-upload;
    although other will still see the 'upload a new..' button.


  • or you can do it without modifying the action file


    elgg_register_action('file/upload', elgg_get_plugins_path() . 'file/actions/file/upload.php', 'admin');

  • thanks matt, that helped me too. :)

  • Another easier option is create a plugin hook for the 'file/upload' action and return false, if the current user is not an admin.

    Single problem, multiple options, selection is yours. :)