Re: Authenticate files downloads

From: Date: Wed, 07 Aug 2002 18:44:14 +0000
Subject: Re: Authenticate files downloads
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-111560@lists.php.net to get a copy of this message
You could put all of the files above your web root and then have your download script read in and spit out the file to the user, so the only way to access the file would be through the download script. Or you could modify your httpd.conf or use htaccess and make it so users cannot access that directory without being refered from the download.php script. (This isn't totally foolproof though as the referer could be spoofed). Something like: SetEnvIf Referer www\.domain\.com/download\.php let_me_in <Directory /var/www/test> <LIMIT GET POST PUT> order deny,allow deny from all allow from env=let_me_in </LIMIT> </Directory> > I'm trying to use php to validate if a user has > permission to download a file. I can restrict them > from accessing the .php file that has the download > links. But how do I stop someone from typing in the > path to the file directly and downloading it. > > > __________________________________________________ > Do You Yahoo!? > Yahoo! Health - Feel better, live better > http://health.yahoo.com > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#111560) next »