Re: how to build restreced area?

From: Date: Sun, 20 Oct 2002 02:53:31 +0000
Subject: Re: how to build restreced area?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-120652@lists.php.net to get a copy of this message
You have heaps of little issues hear, which you need to address one-by-one, then try to get them all integrated. 1. Restricting pages / sessions / user management: I've answered this question maybe 50 times the exact same way. You should check the archives before posting. There is a reasonable tutorial on "restricting selected pages with a login form" by Kevin Yank on sitepoint.com / webmasterbase.com. http://www.webmasterbase.com/article/319 It taught me heaps about sessions, and was the basis for my session/authentication/user management library, which is now in use on heaps of sites. Warning: The code in the article is written for register globals ON, and relies on cookies. You'll need to put in some extra work to overcome these (possible) problems. 2. Restricting files: again, this gets asked constantly... once you have user management, you can restrict files to ONLY members. A good article, which again become the basis of my own code library, can be found on Zend: http://www.zend.com/zend/trick/tricks-august-2001.php on 19/10/02 7:57 PM, marcel.britsch (marcel.britsch@gmx.de) wrote: > hi there, > although I was seeking at serveral sites, I could not find a solution for my > problem. hopefully one of yous has any ides: > > - project: > just a simple client area with restrected acces to folders and their > contents. > structure: a folder called clients. within this folder the admin creates a > folder for every project/client > with a start-page (html or php). this page links to other pages (html), > images or other files within this folder. > the client visits the webpages, is promted to login and is transferred to > his directory. > the files in theses directories must be protected, that it is not possible > to access them by typing the path (although it might be difficult to guess > the path). > > - problem: > my provider runs php as cgi-module (thats how it is called, right?) so (for > me it seems) that there is no access via the environmental or server vars > (sorry I am still new to php), referring to .htaccess. at least these vars > do not exist. > > I am not quite sure how, but I think I could modify the .htaccess files by > just writing into them (although I am not sure, if this is possible, if the > foler is protected). but anyway, my client wants his clients to login via a > user-pwd form. with .htaccess the client would have either to click on a > link (so all clients would have to be listed, which is regarding descrition > not possible) or the client would have to type the path of his directory, > which my client just does not want to. > > - question: > how can I solve this problem? > as my client will create all contents within the clients-folders, and theses > files will be very different everytime, I cant put everything outside the > server-root and create this content by php or use a database. > > how is this usually done? > am I digging in the totally wrong area? > > thank a lot in advance > marcel > >

« previous php.general (#120652) next »