Re: Authorisation
| From: | Michael Teter | Date: | Tue, 04 Jul 2000 22:33:13 +0000 |
| Subject: | Re: Authorisation | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-4828@lists.php.net to get a copy of this message | ||
I'm not sure this is right, but look in the apache
build instructions for auto index or something like
that. I think by default apache will build with the
module that automatically generates a directory index
if there's no index.html.
So if you remove that feature, apache will stop giving
people a look at your directory tree.
There's probably a PHP way to do it, but I'm almost
certain that you can make apache stop providing that
info.
michael
--- Mick Lloyd <mjl@consultingrooms.com> wrote:
> I've followed the recent thread on authorisation and
> have a related
> question. I understand how checking user
> name/password on each page can
> control access without the need for .htaccess in the
> directory where the
> pages reside. However, how can one prevent access to
> the directory through
> the browser without using .htaccess.
>
> For instance, typing www.~.com/~/admin requires
> authorisation when
> ..htaccess is present in /admin but when it is not
> there, it reveals the
> directory listing that anyone can view. How can I
> prevent this happening yet
> authorise users via a form and MySQL database check.
>
> Best regards
>
> Mick Lloyd
> mjl@consultingrooms.com
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail:
> php-general-unsubscribe@lists.php.net
> For additional commands, e-mail:
> php-general-help@lists.php.net
> To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
>
__________________________________________________
Do You Yahoo!?
Kick off your party with Yahoo! Invites.
http://invites.yahoo.com/