Re: Authenticate files downloads
| From: | Rick Baker | Date: | Wed, 07 Aug 2002 18:44:14 +0000 |
| Subject: | Re: Authenticate files downloads | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-111560@lists.php.net to get a copy of this message | ||
You could put all of the files above your web root and then have your
download script read in and spit out the file to the user, so the only way
to access the file would be through the download script.
Or you could modify your httpd.conf or use htaccess and make it so users
cannot access that directory without being refered from the download.php
script. (This isn't totally foolproof though as the referer could be
spoofed). Something like:
SetEnvIf Referer www\.domain\.com/download\.php let_me_in
<Directory /var/www/test>
<LIMIT GET POST PUT>
order deny,allow
deny from all
allow from env=let_me_in
</LIMIT>
</Directory>
> I'm trying to use php to validate if a user has
> permission to download a file. I can restrict them
> from accessing the .php file that has the download
> links. But how do I stop someone from typing in the
> path to the file directly and downloading it.
>
>
> __________________________________________________
> Do You Yahoo!?
> Yahoo! Health - Feel better, live better
> http://health.yahoo.com
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php