Re: Securing a File with php

From: Date: Thu, 30 Nov 2000 08:05:50 +0000
Subject: Re: Securing a File with php
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-27995@lists.php.net to get a copy of this message
Is there a way of securing that document without using a .htaccess file with php. I've tried to move it outside of the /home/html path but could not get it to work.
Save this PHP file (below) as: file.php And follow it with a filename that is safely outside your web root like: http://www.yoursite.com/file.php/stephenkingbook.doc The top few lines parse the URL and make $p = "stephenkingbook.doc" The ONLY way to get at this file will be through your PHP script, which you can use many different methods of securing that from the public. <? // SAFE-MP3 DOWNLOADER /* REQUIRE AUTHORIZATION AT THE TOP HERE, in any password/cookie/phplib method you want. */ // then... if (strstr($PATH_INFO, "/")) { $p = substr($PATH_INFO, 1); $fullpath = "/something/outside/webroot/" . $p; if (file_exists($fullpath))
        {
        header("Content-Type: application/download\n");
        header("Content-Disposition: filename=\"$p\"");
        header("Content-Transfer-Encoding: binary");
        $fn=fopen($fullpath, "r");
        fpassthru($fn);
        }
else
        {
        print "not found";
        die();
        }
} else { print "you need a filename"; } ?> -- linuxbaby@yahoo.com

« previous php.general (#27995) next »