Authorisation
| From: | Mick Lloyd | Date: | Tue, 04 Jul 2000 09:50:16 +0000 |
| Subject: | Authorisation | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-4701@lists.php.net to get a copy of this message | ||
I've followed the recent thread on authorisation and have a related
question. I understand how checking user name/password on each page can
control access without the need for .htaccess in the directory where the
pages reside. However, how can one prevent access to the directory through
the browser without using .htaccess.
For instance, typing www.~.com/~/admin requires authorisation when
.htaccess is present in /admin but when it is not there, it reveals the
directory listing that anyone can view. How can I prevent this happening yet
authorise users via a form and MySQL database check.
Best regards
Mick Lloyd
mjl@consultingrooms.com