set htaccess user & pw from php code
| From: | news.php.net | Date: | Mon, 11 Feb 2002 16:06:48 +0000 |
| Subject: | set htaccess user & pw from php code | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-84289@lists.php.net to get a copy of this message | ||
While looking around the doc's and newsgroups I found many examples how to
envoke a auth-popup in the browser and then reading username and password
passed over from that authentification in php.
What I want is basicly the opposite.
I've got a finished and implemented solution with authentification to a
mySQL-db, using a form for entering username and password.
Now my customer want's a new function on the site: file downloads for
certain users. my problem is: how can I secure the files so nobody can just
download them by guessing the url?
my approach was to keep the auth system I'm running now and adding .htaccess
files to various dirs automaticly from the mysql user-db and enforcing an
athentification from php to the webserver without the auth-popup ever
turning up on the client browser.
Something like this:
$HTTP_SERVER_VARS['AUTH_USER'] = $myUserName
$HTTP_SERVER_VARS['AUTH_PASSWORD'] = $myUserPass
now the user can access files corresponding to the .htaccess files on the
webserver for the duration of this session...
Is this possible?
Perhaps there is a much better solution of securing files from unauthorized
users I missed. possebly storing the file outside of the webdir on the
server and streaming them through php for download... or so.
any hints?
the site is hosted on a zeus webserver with php(3.0.14) in cgi-mode.
tnx for your advice
steven