RE: [PHP] protecting downloads with php
| From: | Miguel Cruz | Date: | Sat, 11 May 2002 17:05:25 +0000 |
| Subject: | RE: [PHP] protecting downloads with php | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-97138@lists.php.net to get a copy of this message | ||
If you don't tell anyone what the secret path is, it's as good as a
password.
miguel
On Sat, 11 May 2002, John Holmes wrote:
> Store your files outside of the webroot if you use this method. Then
> they can't type in the address directly (otherwise this doesn't fix
> anything).
>
> ---John Holmes...
>
> > -----Original Message-----
> > From: Miguel Cruz [mailto:mnc@stoic.net]
> > Sent: Saturday, May 11, 2002 2:23 AM
> > To: PHP-General
> > Subject: Re: [PHP] protecting downloads with php
> >
> > download.php:
> >
> > <?
> >
> > if (userIsAuthorized)
> > {
> > header('Content-Type: application/x-gzip');
> > readfile('secret-name-of-file.tar.gz');
> > exit;
> > }
> > else
> > {
> > print 'You are not authorized to download this file.';
> > }
> >
> > ?>
> >
> > Season to taste with GET arguments such as an ID number or other hash
> > identifying which file to send.
> >
> > miguel
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>