RE: [PHP] auth_user and auth_pw through URL
| From: | Adam Cantrell | Date: | Mon, 21 Aug 2000 19:05:21 +0000 |
| Subject: | RE: [PHP] auth_user and auth_pw through URL | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12785@lists.php.net to get a copy of this message | ||
It's actually accessing files (temporary attachment repositry for a web
based message center) that I am trying to restrict, so I need the overall
directory to be restricted. Do you know of a way I could serve the file up
to the browser without directly linking to it? Is there a way to access the
directory structure and serve up files from a php template so that the
browser has no idea where the file was pulled from?
> -----Original Message-----
> From: Dave Daniels [mailto:dave@musiccity.net]
> Sent: Monday, August 21, 2000 2:02 PM
> To: Adam Cantrell; php-general@lists.php.net
> Subject: Re: [PHP] auth_user and auth_pw through URL
>
>
> You might have to take a different approach. I would recommend creating a
> session when the user logs in through your form (which you should probably
> verify against a db) and some kind of validation on the private pages.
>
> ----- Original Message -----
> From: "Adam Cantrell" <adamc@scribe.com>
> To: <php-general@lists.php.net>
> Sent: Monday, August 21, 2000 1:57 PM
> Subject: [PHP] auth_user and auth_pw through URL
>
>
> >
> > Is there a way I can pass the auth_user and auth_pw variables as URL
> > variables that are masked? What i would like, is something that looks
> like
> > this www.url.com?username=****&pass=**** where the **** strings are
> masked.
> > I don't want the browser's basic authentication window to pop up because
> the
> > user has already logged in through our web based form over SSL. I just
> want
> > a way for the files to be accessable, but I don't want users to
> be able to
> > just copy the URL and send it to their friends - or just guess
> file names.
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-general-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
>
>