How to keep unauthorized viewers out

From: Date: Tue, 16 Jan 2001 23:49:29 +0000
Subject: How to keep unauthorized viewers out
Groups: php.general 
Request: Send a blank email to php-general+get-34924@lists.php.net to get a copy of this message
I'm using a pretty simple linking system for a subscription-based newsletter site. Stories and articles are in straight html files, reached by links from the front page. Clicking on a link passes a story number. So the second story on the index page would have this link: <A HREF="./story.php?storynum=2"> and story.php consists of just these lines: <? include "auth.inc" ; include "header.inc" ; include $storynum.".htm" ; include "footer.inc" ; ?> If someone comes in the "right way", through the index page, they will have to be authenticated, then the header, article and page footer are displayed. There's nothing, however, to stop someone from typing an URL like this: http://www.somepub.ca/2.htm and seeing the article. I assume they could also come in that way via a search engine. Any suggestions on how to stop that? Resources I should look at? I do want to keep the stories in straight html as the editor is struggling now with basic layout, etc. Regards - Miles Thompson

« previous php.general (#34924) next »