Jump to content

[SOLVED] Security question


realjumper

Recommended Posts

Hi,

 

My website has a secure login section via ssl. None of the subsequent php pages can be accessed with being logged in, which is as intended. But, documents, such as pdf files etc, can be accessed directly via the url if you know the url (obviously!). How do I protect these files to prevent people from accessing them without logging in first?

Link to comment
https://forums.phpfreaks.com/topic/149051-solved-security-question/
Share on other sites

Put the files out of the web root and make people go through a PHP script to get to them.

 

 

Logical flow:

 

-Person requests file.php?file=blah

-Script reads and outputs the file based on the parameter if the user is logged in.

 

(You will want to make sure to validate that the parameter is valid.)

Put the files out of the web root and make people go through a PHP script to get to them.

 

 

Logical flow:

 

-Person requests file.php?file=blah

-Script reads and outputs the file based on the parameter if the user is logged in.

 

(You will want to make sure to validate that the parameter is valid.)

 

Thanks Corbin, that's more or less what I was thinking I would have to do.

 

Many thanks

 

Yep, mod_rewrite might be an option, but I like Corbins suggestion too. Don't want to use .htaccess.

 

Thanks for your help

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.