Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
PHP Directory Download Permissions
Old 01-05-2009, 08:41 PM PHP Directory Download Permissions
cbeaudin's Avatar
Extreme Talker

Posts: 158
Name: cbeaudin
Location: Proud to be Canadian
Trades: 1
I have a website that is group oriented and allows members to upload files within the groups that they are a part of. I am trying to find a way to make sure that only members of that group can download the files that belong to that group. Members must authenticate and be a member of the group to even view the links to the files, but how do i stop someone from just manually typing in the address to the file name in the address bar without .htaccess?

Is there a way to allow only read permissions to localhost and have the php page send the file to authenticated users?

Thank you for any replies.
__________________
- cbeaudin
cbeaudin is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 01-05-2009, 08:45 PM Re: PHP Directory Download Permissions
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,517
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
http://www.webmaster-talk.com/coding...rectories.html
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 01-05-2009, 08:52 PM Re: PHP Directory Download Permissions
cbeaudin's Avatar
Extreme Talker

Posts: 158
Name: cbeaudin
Location: Proud to be Canadian
Trades: 1
Thank you for the quick reply.

There must be a more secure way of doing this. Whats to stop a bot or program from grabbing all the files at once?
__________________
- cbeaudin
cbeaudin is offline
Reply With Quote
View Public Profile
 
Old 01-05-2009, 09:02 PM Re: PHP Directory Download Permissions
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,517
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
If the URIs are never publicly exposed how will a bot know where they are?

It's relatively simple matter to push files out from any URI without exposing the files actual location.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 01-05-2009, 09:16 PM Re: PHP Directory Download Permissions
cbeaudin's Avatar
Extreme Talker

Posts: 158
Name: cbeaudin
Location: Proud to be Canadian
Trades: 1
I see what your saying, but that seems pretty insecure in my opinion. There are some websites out there that offer online hard drive space without .htaccess. I would like to think they have something a little more secure than hiding the URI, or i could be wrong. Even with hiding the URI, being able to download something that could contain sensitive information without authenticating seems to be asking for trouble.
__________________
- cbeaudin
cbeaudin is offline
Reply With Quote
View Public Profile
 
Old 01-06-2009, 01:15 PM Re: PHP Directory Download Permissions
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,517
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
Quote:
Even with hiding the URI, being able to download something that could contain sensitive information without authenticating seems to be asking for trouble.
That's the purpose of using sessions and/or cookies.
If the session/cookies carries the correct information they get the file, otherwise they get told to "go away".

The page that does the authentication also does the download by setting the contenttype and requesting the file, that way ALL files are accessed via /download/?fileref=whatever. The real location of the file is never exposed, all the file refs/URIs are in a database and if needs be can be changed at a moments notice. You can track the downloads to each registered user and the files can be located on any server, anywhere. Which may or may not be the same server as the download page is.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Reply     « Reply to PHP Directory Download Permissions
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.23118 seconds with 12 queries