Is there a way of securing that document
without using a .htaccess file with php. I've tried
to move it outside of the /home/html path but could
not get it to work.
Save this PHP file (below) as:
file.php
And follow it with a filename that is safely outside your web root like:
http://www.yoursite.com/file.php/stephenkingbook.doc
The top few lines parse the URL and make $p = "stephenkingbook.doc"
The ONLY way to get at this file will be through your PHP script, which you can use many different methods of securing that from the public.
<?
// SAFE-MP3 DOWNLOADER
/* REQUIRE AUTHORIZATION AT THE TOP HERE, in any password/cookie/phplib method you want. */
// then...
if (strstr($PATH_INFO, "/"))
{
$p = substr($PATH_INFO, 1);
$fullpath = "/something/outside/webroot/" . $p;
if (file_exists($fullpath))
{
header("Content-Type: application/download\n");
header("Content-Disposition: filename=\"$p\"");
header("Content-Transfer-Encoding: binary");
$fn=fopen($fullpath, "r");
fpassthru($fn);
}
else
{
print "not found";
die();
}
}
else
{
print "you need a filename";
}
?>
--
linuxbaby@yahoo.com