Re: Files only available via HTTPS
| From: | Nathan Crause | Date: | Fri, 02 Feb 2001 17:41:54 +0000 |
| Subject: | Re: Files only available via HTTPS | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-37874@lists.php.net to get a copy of this message | ||
I think your best bet would be to use cookies tagged as secure. My
understanding is that if a cookie is tagged as secure, then the web server
should not give any scripting language access to it (i.e. if you have a
secure cookie LOGGEDIN, then PHP would NOT have $LOGGEDIN set [use isset] if
the user tries to use HTTP instead of HTTPS).
"Michael Conley" <mconley@RentHistory.com> wrote in message
news:2102328FD2ECD411879E00609737BFD11C83@FATBOY...
> I have several PHP files that I only want users to be able to access via
> HTTPS. How can I control that on an Apache 1.3.14 server running on
RedHat
> 7? I have openssl and mod_ssl working fine. Currently, I can access all
of
> the files on my site via either http or https. I want to keep certain
files
> (with interesting information) from being accessed via http. I realize
this
> isn't really a PHP question, but I have no idea how to do this.
>
> Thanks.
>
>
----------------------------------------------------------------------------
----
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net