Protect media requests

Last updated Friday, February 26, 2016 in Sitecore Experience Platform for Developer, Administrator

The media request protection feature restricts media URLs that contain dynamic image-scaling parameters, so that only server-generated requests are processed. This ensures that the server only spends resources and disk space on valid image-scaling requests.

You can make your solution more secure and use the Sitecore media request protection feature optimally, if you make a small change to the Sitecore.Media.RequestProtection.config file.

To optimize the media request protection feature:

  • Open the /App_Config/Include/Sitecore.Media.RequestProtection.config file and change the Media.RequestProtection.SharedSecret setting to a random string.

Note

In a multiserver setup, you must use the same value for the Media.RequestProtection.SharedSecret setting on every server. This ensures that dynamic image scaling works correctly in situations where one server generates the image URL and another handles the request.

Send feedback about the documentation to docsite@sitecore.net.