Antivirus
Antivirus scans every file uploaded to WinnerWare and blocks anything unsafe before it's ever saved. It works quietly in the background — there's nothing for end users to do differently, and nothing to review afterward, because a bad file simply never makes it into the system.
Overview
Whenever someone uploads a file to WinnerWare — an attachment on a content item, a knowledge base document, an import, or any other upload — this module sends a copy of it to SophosLabs Intelix, a third-party malware-scanning service, before the file is written to storage. If Intelix reports the file as malicious or suspicious, the upload is rejected with a plain error message instead of being saved.
This module has no admin screen. It is turned on and configured entirely through the site's application settings, so setting it up is an IT/hosting task rather than something an administrator does from the WinnerWare admin UI.
Key Features
- Scans every file upload across the site before it is stored.
- Rejects malware and known-bad files automatically, with no manual review step.
- Reuses previous scan results for a file that's been seen before (by its content, not its name), so re-uploading the same file doesn't re-scan it from scratch.
- Falls back safely: if no scanning credentials are configured, uploads simply proceed unscanned instead of failing.
How It Works
- When a file is uploaded, WinnerWare hands a copy of it to the scanner before writing it to storage.
- The scanner checks whether it has already scanned that exact file before. If so, it reuses that result.
- Otherwise, it submits the file to SophosLabs Intelix and waits for a verdict, checking back periodically until the scan finishes or a timeout is reached.
- Intelix returns a safety score from 0 (malicious) to 100 (benign). WinnerWare compares that score against a configured threshold:
| Score range | Category | Result |
|---|---|---|
| 0–19 | Malware | Upload rejected |
| 20–29 | Potentially Unwanted Application | Upload rejected |
| 30–69 | Unknown | Accepted by default (threshold is 30) — raise the threshold to reject these too |
| 70–100 | Known clean | Upload accepted |
If the file is rejected, the person uploading it sees a generic message explaining the file was blocked by the antivirus scanner — internal scoring details are never shown to end users, though they are recorded in the server logs for an administrator to review.
Configuration
There is no in-app settings screen for this module. It's configured by adding a section to the site's application settings which is typically done by whoever manages the hosting environment:
| Setting | Purpose |
|---|---|
| Provider | Must be SophosLabs — this is the only provider this module can use for scanning uploads (see Important notes). |
| ClientId / ClientSecret | The credentials for your SophosLabs Intelix account. Scanning is skipped (uploads pass through unscanned) until both are set. |
| Region | The Sophos Intelix regional endpoint to use. |
| CleanScoreThreshold | The minimum score (0–100) a file must reach to be accepted. The default, 30, accepts unrecognized files along with known-clean ones. Raise it to 70 to only accept files Sophos has positively identified as clean. |
| AnalysisTimeoutSeconds / PollingIntervalSeconds | How long to wait for a scan result, and how often to check back while waiting. |
Until ClientId and ClientSecret are both provided, this module has no effect — every upload proceeds exactly as it would without it.
Usage
Turn this on for any WinnerWare site that accepts file uploads from users who aren't fully trusted — attachments, imported documents, knowledge base files, and similar. Because it runs on every upload site-wide, there's no per-module or per-content-type toggle to manage separately.
Important notes
- This module integrates with SophosLabs Intelix, a direct file-scanning API — it does not work with the general Sophos Central product used to manage endpoint antivirus software. Sophos Central credentials will not work here.
- If a file is rejected, it is rejected at upload time. There's no quarantine or approval queue — the person uploading needs to confirm the file is legitimate and try again, or contact an administrator if they believe it was blocked incorrectly.
Developer Notes
- Registers an
IFileEventHandlerthat intercepts every file creation through Orchard Core's file storage pipeline. - The legacy configuration section name
Antivirus:Sophosis still read for backward compatibility ifCloudSolutions_Antivirus_Sophosisn't set. - Sophos authentication tokens are cached and refreshed automatically; the current token state is stored in a protected document rather than in plain configuration.