October 28, 201411 yr Hi, I have written a series of webpages in php that I want to link to from other pages on my site, but I don't want anyone to be able to browse directly to them. Would the best way to achieve this be to store the pages in a directory outside the public html area and if so how do I link to them from other pages on the site? Or would a better way be to store them in a public directory with htaccess blocking access to them, and if so how do I make sure my other pages can still open them (I hope that makes sense!)Thanks in advance
October 28, 201411 yr If you apply some form of access control via a log in script that should do it. If someone attempts to directly access the URL of the page they will be redirected to the log in page.
October 28, 201411 yr Author If you apply some form of access control via a log in script that should do it. If someone attempts to directly access the URL of the page they will be redirected to the log in page. Hi thanks for the reply but that won't work in this case, They have an existing site built in Joomla and I am going to link to these external scripts from within the joomla site. What I need to do is allow access to these pages for people who are logged into the joomla site, so far so good, thats not a problem, but what I want to do is stop people copying the url into a browser and seeing the page without going through the joomla login first, so I want to allow access if called from the same domain but not from anywhere else. Is that possible?
October 31, 201411 yr Hi thanks for the reply but that won't work in this case, They have an existing site built in Joomla and I am going to link to these external scripts from within the joomla site. What I need to do is allow access to these pages for people who are logged into the joomla site, so far so good, thats not a problem, but what I want to do is stop people copying the url into a browser and seeing the page without going through the joomla login first, so I want to allow access if called from the same domain but not from anywhere else. Is that possible? I'm not that familiar with Joomla but I would have thought that its log in system would employ PHP sessions if so the page would require a valid session to be set to true in order for it to display. If the URL is directly accessed in a browser it should, if a valid session is not in force, either display a message to go to the home page or log in page or simply redirect to the log in page.
October 31, 201411 yr If Joomla runs a login I'm 90% sure it's using cookies. When they login they will be issued a session. <?php $sid = session_id(); if($sid!="") { echo "I have a session id! It's " . $sid; } else { echo "No session"; // So add a redirect to the login page } ?> This is a 'simple' version, no idea what a Joomla session sets but this will check for a session. No doubt Joomla will have timeouts, user data etc but this will serve to stop direct access to a page.
Create an account or sign in to comment