Re: protecting real files

From: Date: Sun, 30 Jul 2000 21:42:29 +0000
Subject: Re: protecting real files
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-9073@lists.php.net to get a copy of this message
> Unfortunately, my webhost allows only HTTP streaming.. and I was wondering.. > how is it that I'm supposed to stop users (or unallow them) from downloading > my real files? I'm using Unix... > > Basically, what are the functions I should have in my php script to play > these files so that its a good one :-) Check out the readfile() function. You could use it something like this: if (HasAccess($RealFileName, $UserID)) { header("Content-Type: some/real-type"); readfile("/directory/which/is/no/accessible/via/the/webserver/$RealFileName" ); } Then, instead of directly embedding the real file you'd do something like <EMBED SRC="send_real.php?RealFileName=my_file.ra">.

« previous php.general (#9073) next »