Thanks Stephen. If Joe user guesses the path to the files, he'll be able to access them though, which is what I want to avoid.

eg. If the path to the PDF docs is www.mycompany.com/PDFs/

and Joe user guesses that a file name is report1.pdf and then enters www.mycompany.com/PDFs/report1.pdf into his browser, he's gonna get the file. Right? I realise that someone guessing the directory name and the filename is not that high, but still. What do other people do about this?

Cheers,
Clancy


From: Stephen Caudill <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Subject: [wdvltalk] Re: Programmatical authentication for .htaccess
Date: Fri, 13 Aug 2004 10:29:45 -0400

Forget .htaccess.  Just don't put the files in the web root.  Most
hosting packages allow you at least some access to the file system
outside of the web site's root, so stick the file there.  Your scripts
will still have access to it, but Joe Browser won't...

hth,
Stephen

On Thu, 12 Aug 2004 18:18:29 -0700, [EMAIL PROTECTED]
<[EMAIL PROTECTED]> wrote:
<snip/>
> Any other suggestions?

____ � The WDVL Discussion List from WDVL.COM � ____
To Join wdvltalk, Send An Email To: mailto:[EMAIL PROTECTED]
Send Your Posts To: [EMAIL PROTECTED]
To set a personal password send an email to [EMAIL PROTECTED] with the words: "set WDVLTALK pw=yourpassword" in the body of the email.
To change subscription settings to the wdvltalk digest version:
http://wdvl.internet.com/WDVL/Forum/#sub


________________  http://www.wdvl.com  _______________________

You are currently subscribed to wdvltalk as: [EMAIL PROTECTED]
To unsubscribe send a blank email to %%email.unsub%%

To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.


_________________________________________________________________
There�s never been a better time to get Xtra JetStream @ http://xtra.co.nz/jetstream



____ � The WDVL Discussion List from WDVL.COM � ____
To Join wdvltalk, Send An Email To: mailto:[EMAIL PROTECTED] Send Your Posts To: [EMAIL PROTECTED]
To set a personal password send an email to [EMAIL PROTECTED] with the words: "set WDVLTALK pw=yourpassword" in the body of the email.
To change subscription settings to the wdvltalk digest version:
http://wdvl.internet.com/WDVL/Forum/#sub


________________  http://www.wdvl.com  _______________________

You are currently subscribed to wdvltalk as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.



Reply via email to