Hello Friends, i have build an Application, where I give
option to download files from my website, ok I hav provided alink
to the file on my server's directory which is called as downloads,
i want the user should able to get that file when he clicks the
download button, means he should get the zipped file, ok he tries
other means like browing the FTP folder straight away using any ftp
manager or straight into the web browser, he should not be able to
edit anything. instead get an error.
I'm not sure if I understand what you're asking, but I'll try
1) Move downloads directory outside the webroot.
2) Create a download script which uses
to serve the requested file (with the name defined in url scope or
3a) In the download script, add a check for CGI.HTTP_REFERER,
and ensure it is the page that the download link is on, else
redirect to that page. (will not work for some clients)
3b) In the download script, add a check for a session
variable that is set by the page the download link is on, and
redirect if not found.
3c) In the download script, add a check for an encrypted url
variable that expires after a period of time.