I want authorized users to be able to download MP3 files (yes they're legal) that I keep stored outside the Apache webroot, so that people can only play/download them if the PHP script has authorized them.
Answered my own question: (sorry!)
Here's a file called "mp3.php", which must be followed by a slash, then the name of your MP3 file.
EXAMPLE:
http://www.yoursite.com/mp3.php/Some_Song_Name.mp3
if (strstr($PATH_INFO, "/"))
{
$p = substr($PATH_INFO, 1);
$fullpath = "/www/safe-mp3/" . $p;
if (file_exists($fullpath))
{
header("Content-Type: application/download\n");
header("Content-Disposition: filename=\"$p\"");
header("Content-Transfer-Encoding: binary");
$fn=fopen($fullpath, "r");
fpassthru($fn);
}
else
{
print "not found";
die();
}
}
else
{
print "you need a filename";
}