set htaccess user & pw from php code

From: Date: Mon, 11 Feb 2002 16:06:48 +0000
Subject: set htaccess user & pw from php code
Groups: php.general 
Request: Send a blank email to php-general+get-84289@lists.php.net to get a copy of this message
While looking around the doc's and newsgroups I found many examples how to envoke a auth-popup in the browser and then reading username and password passed over from that authentification in php. What I want is basicly the opposite. I've got a finished and implemented solution with authentification to a mySQL-db, using a form for entering username and password. Now my customer want's a new function on the site: file downloads for certain users. my problem is: how can I secure the files so nobody can just download them by guessing the url? my approach was to keep the auth system I'm running now and adding .htaccess files to various dirs automaticly from the mysql user-db and enforcing an athentification from php to the webserver without the auth-popup ever turning up on the client browser. Something like this: $HTTP_SERVER_VARS['AUTH_USER'] = $myUserName $HTTP_SERVER_VARS['AUTH_PASSWORD'] = $myUserPass now the user can access files corresponding to the .htaccess files on the webserver for the duration of this session... Is this possible? Perhaps there is a much better solution of securing files from unauthorized users I missed. possebly storing the file outside of the webdir on the server and streaming them through php for download... or so. any hints? the site is hosted on a zeus webserver with php(3.0.14) in cgi-mode. tnx for your advice steven

« previous php.general (#84289) next »