Jump to content

Tell me why this wont work


optikalefx

Recommended Posts

im making a script for downloading files that have been purchased.

On the download page...

 

call a php file passing the transaction id

download.php?file=2234234982374982734892739842

 

in download.php

go though the db, select that transaction

 

check that the session[userid] matches the id of the userid who made that transaction

 

if it does, serve the zip file to the user

 

Using this method, it requires the user to be logged in to be able to click his download link.  So he can't just pass the link around.  Also, he can log in and re download the file as many times as he wants, because he is logged in.

 

Anyone find any holes in this method?

 

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.