dongling4383 2009-05-31 20:30 采纳率: 100%
浏览 16
已采纳

没有.htaccess的安全目录密码保护

I was going to use .htaccess to password protect a directory for a php script I'm writing, as I do not trust my PHP skills to create a secure login, but I found out you cannot use relative paths for AuthUserFile and I could not generalize this.

If you could direct me to a secure PHP login script to password protect a directory I would be very grateful. Thanks.

  • 写回答

2条回答 默认 最新

  • douxun4924 2009-05-31 20:48
    关注

    One thing you can do is keep all your "secret" files in a directory outside of the server's webroot. All access to these files can then be routed through a single PHP-script inside your directory. Something like this:

    http://www.example.com/protected-directory/access.php?file=/foo/document.doc

    With a directory structure such as this:

    +--+ /server_root
       |
       +--+ /web_root
       |  |
       |  +--+ /protected-directory
       |     +-- access.php
       |     +-- access-denied.html
       |
       +--+ /protected_root
          |
          +--+ /foo
             +-- document.doc
    

    In your access.php you would do something like this:

    $file = $_REQUEST['file'];
    if ($user->hasAccessTo($file)) {
        readfile("/server_root/protected_root/$file");
    } else {
        readfile('access-denied.html');
    }
    

    Now, you have to be careful that you make sure nobody screws with your file-parameter and passes something along like "../../../etc/passwd". Also, you probably want to make sure you send the correct headers in the above example, I omitted that for reasons of clarity.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥20 测距传感器数据手册i2c
  • ¥15 RPA正常跑,cmd输入cookies跑不出来
  • ¥15 求帮我调试一下freefem代码
  • ¥15 matlab代码解决,怎么运行
  • ¥15 R语言Rstudio突然无法启动
  • ¥15 关于#matlab#的问题:提取2个图像的变量作为另外一个图像像元的移动量,计算新的位置创建新的图像并提取第二个图像的变量到新的图像
  • ¥15 改算法,照着压缩包里边,参考其他代码封装的格式 写到main函数里
  • ¥15 用windows做服务的同志有吗
  • ¥60 求一个简单的网页(标签-安全|关键词-上传)
  • ¥35 lstm时间序列共享单车预测,loss值优化,参数优化算法