Authorisation

From: Date: Tue, 04 Jul 2000 09:50:16 +0000
Subject: Authorisation
Groups: php.general 
Request: Send a blank email to php-general+get-4701@lists.php.net to get a copy of this message
I've followed the recent thread on authorisation and have a related question. I understand how checking user name/password on each page can control access without the need for .htaccess in the directory where the pages reside. However, how can one prevent access to the directory through the browser without using .htaccess. For instance, typing www.~.com/~/admin requires authorisation when .htaccess is present in /admin but when it is not there, it reveals the directory listing that anyone can view. How can I prevent this happening yet authorise users via a form and MySQL database check. Best regards Mick Lloyd mjl@consultingrooms.com

« previous php.general (#4701) next »