Re: Protecting a folder
This WebDNA talk-list message is from 2000
It keeps the original formatting.
numero = 35718
interpreted = N
texte = I would be very surprised if resetting the header can do it. The only way (Iknow) to change user and password on the fly is to put them into the URL:http://myname:mypass@www.server.com/download/...But how to hide this? Frames won't fool an experienced user, neither arefresh. And you can't encrypt this part of the URL.Sorry, I have no other idea yet than the move/rename approach. If the filesare not really huge and you can't have a folder outside the root I would tryit: for testing name the files like filename.db which prevents delivery byyour Webstar.The following assumes you have a folder /download/ which holds youroriginal .sit files but all with the suffix .db1 - Deliver a faked listing:[listfiles /download/][getchars start=3&from=end][filename].sit[/getchars]
[/listfiles](so the user will never see a .db extension)Yes, the download must point to a template, not to a file.2 - User clicks on a link.3 - Create a temporary folder [SessionID]4 - Move /download/filename.db to /[SessionID]/filename.temp5 - WaitForFile /[SessionID]/filename.temp6 - Rename it to /[SessionID]/filename.sit7 - Redirect to this file, this starts the downloadLater you will find a chance to remove the SessionID from the user anddelete filename.sit plus the temporary folder.We are on Linux now with most servers and I'm not sure if copying largefiles is a good idea on newer Mac's. And you might not need the abovetemp-sit-renaming on Mac after the copy. On Linux I do, because the fileemerges immediately and [waitforfile] sees it to early.Hope, this is worth a try :)Peter---> From: Stuart Tremain
> Reply-To: (WebCatalog Talk)> Date: 04 Aug 2000 10:27:33> To: (WebCatalog Talk)> Subject: Re: Protecting a folder> > I'm using [ListFiles] to display what is available.> > The files are accessible from a protected template. I basically don't want> people to access them without going through the template as it logs their> access etc etc and the visitor would be able to access the folder directly if> I can't protect it.> > Are the ID & pasword passed by the browser in the header, could I reset the> header to include a generic password to get them into the realm from the> template? Would this be secure enough?-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/
Associated Messages, from the most recent to the oldest:
I would be very surprised if resetting the header can do it. The only way (Iknow) to change user and password on the fly is to put them into the URL:http://myname:mypass@www.server.com/download/...But how to hide this? Frames won't fool an experienced user, neither arefresh. And you can't encrypt this part of the URL.Sorry, I have no other idea yet than the move/rename approach. If the filesare not really huge and you can't have a folder outside the root I would tryit: for testing name the files like filename.db which prevents delivery byyour Webstar.The following assumes you have a folder /download/ which holds youroriginal .sit files but all with the suffix .db1 - Deliver a faked listing:[listfiles /download/][getchars start=3&from=end][filename].sit[/getchars]
[/listfiles](so the user will never see a .db extension)Yes, the download must point to a template, not to a file.2 - User clicks on a link.3 - Create a temporary folder [SessionID]4 - Move /download/filename.db to /[SessionID]/filename.temp5 - WaitForFile /[SessionID]/filename.temp6 - Rename it to /[SessionID]/filename.sit7 - Redirect to this file, this starts the downloadLater you will find a chance to remove the SessionID from the user anddelete filename.sit plus the temporary folder.We are on Linux now with most servers and I'm not sure if copying largefiles is a good idea on newer Mac's. And you might not need the abovetemp-sit-renaming on Mac after the copy. On Linux I do, because the fileemerges immediately and [waitforfile] sees it to early.Hope, this is worth a try :)Peter---> From: Stuart Tremain > Reply-To: (WebCatalog Talk)> Date: 04 Aug 2000 10:27:33> To: (WebCatalog Talk)> Subject: Re: Protecting a folder> > I'm using [listfiles] to display what is available.> > The files are accessible from a protected template. I basically don't want> people to access them without going through the template as it logs their> access etc etc and the visitor would be able to access the folder directly if> I can't protect it.> > Are the ID & pasword passed by the browser in the header, could I reset the> header to include a generic password to get them into the realm from the> template? Would this be secure enough?-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/
Peter Ostry
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Lots of bounce errors (2007)
HomePage Caution (1997)
PCS Customer submissions ? (1997)
Server IP Address (2003)
Announce: WebMerchant 3.0 for Mac shipping now (1998)
Add to a field (1998)
Next (1997)
WebCat editing, SiteGuard & SiteEdit (1997)
WebCat2.0 [format thousands .0f] no go (1997)
Major problem (1999)
Sendmail truncation in Eudora Clients (1998)
Cannot calculate prices (1997)
WC2b15 File Corruption (1997)
HELP! Search finding too much! (1998)
Credit card processing - UK (1997)
A question on sub-categories (1997)
How to implement 'email to a friend' feature? (2002)
emailer (1997)
PSC recommends what date format yr 2000??? (1997)
Many $WebCat.exe processes (1998)