Re: Securing a File with php
| From: | Ignacio Vazquez-Abrams | Date: | Tue, 28 Nov 2000 19:14:43 +0000 |
| Subject: | Re: Securing a File with php | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-27663@lists.php.net to get a copy of this message | ||
On Tue, 28 Nov 2000, Mike Mike wrote:
> I have something like that where the php file will ask
> for a password if you go straight to the page. Like
> for example:
> if i typed
> http://www.somewhere.com/~mike/upnorth/somefile.php
> it would bring up a login screen and ask for a
> password. But if i typed
> http://www.somewhere.com/~mike/upnorth/word.doc
> you can view that word document without a login screen
> showing up.
> Is there a way to do this in php to avoid viewing the
> word document securely without the .htaccess file? The
> problem I'm having is if I do secure the directory
> with a .htaccess file it asks for the password 2
> times. One for the php file and one for the
> directory. I'm trying to get away with the 2nd login
> screen wich the .htaccess file creates.
> Thanks
>
Use another script to pass it through:
<?php
if ((!LOGGEDIN) or empty($HTTP_GET_VARS["file"]))
bounce_to_index_page();
$file=str_replace("../", "", $HTTP_GET_VARS["file"]);
$file=str_replace("..\\", "", $file);
readfile("/data/".$file);
?>
Then you would access a file "/data/somefile.doc" as
"http://.../script.php3?file=somefile.doc".
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>