Re: auth_user and auth_pw through URL
| From: | Dave Jones | Date: | Tue, 22 Aug 2000 03:33:53 +0000 |
| Subject: | Re: auth_user and auth_pw through URL | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12868@lists.php.net to get a copy of this message | ||
How about simply using:
<?php
$thefilename = (some stuff to figure out the filename)
include($thefilename);
?>
Just have that on the page (no <html> or <body> or anything else), since
that will all come from the other page. The browser will think it's on
your php page (actually it really is) but what the viewer sees comes
from whatever page you included.
...Dave
Adam Cantrell wrote:
>
> It's actually accessing files (temporary attachment repositry for a web
> based message center) that I am trying to restrict, so I need the overall
> directory to be restricted. Do you know of a way I could serve the file up
> to the browser without directly linking to it? Is there a way to access the
> directory structure and serve up files from a php template so that the
> browser has no idea where the file was pulled from?
>
> > -----Original Message-----
> > From: Dave Daniels [mailto:dave@musiccity.net]
> > Sent: Monday, August 21, 2000 2:02 PM
> > To: Adam Cantrell; php-general@lists.php.net
> > Subject: Re: [PHP] auth_user and auth_pw through URL
> >
> >
> > You might have to take a different approach. I would recommend creating a
> > session when the user logs in through your form (which you should probably
> > verify against a db) and some kind of validation on the private pages.
> >
> > ----- Original Message -----
> > From: "Adam Cantrell" <adamc@scribe.com>
> > To: <php-general@lists.php.net>
> > Sent: Monday, August 21, 2000 1:57 PM
> > Subject: [PHP] auth_user and auth_pw through URL
> >
> >
> > >
> > > Is there a way I can pass the auth_user and auth_pw variables as URL
> > > variables that are masked? What i would like, is something that looks
> > like
> > > this www.url.com?username=****&pass=**** where the **** strings are
> > masked.
> > > I don't want the browser's basic authentication window to pop up because
> > the
> > > user has already logged in through our web based form over SSL. I just
> > want
> > > a way for the files to be accessable, but I don't want users to
> > be able to
> > > just copy the URL and send it to their friends - or just guess
> > file names.
> > >
> > >
> > > --
> > > PHP General Mailing List (http://www.php.net/)
> > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> > > For additional commands, e-mail: php-general-help@lists.php.net
> > > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> > >
> >
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
--------------------
To send e-mail to me replace the
domain name with djdesign.com
The phony "anti.spam" domain
is used to fool newsgroup e-mail
address harvestor 'bots.
----------------------