Re: protecting real files
| From: | Chris Adams | Date: | Sun, 30 Jul 2000 21:42:29 +0000 |
| Subject: | Re: protecting real files | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-9073@lists.php.net to get a copy of this message | ||
> Unfortunately, my webhost allows only HTTP streaming.. and I was
wondering..
> how is it that I'm supposed to stop users (or unallow them) from
downloading
> my real files? I'm using Unix...
>
> Basically, what are the functions I should have in my php script to play
> these files so that its a good one :-)
Check out the readfile() function. You could use it something like this:
if (HasAccess($RealFileName, $UserID)) {
header("Content-Type: some/real-type");
readfile("/directory/which/is/no/accessible/via/the/webserver/$RealFileName"
);
}
Then, instead of directly embedding the real file you'd do something like
<EMBED SRC="send_real.php?RealFileName=my_file.ra">.