Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #2482 > unrolled thread

Restricting access to a website

Started byGraham Hobbs <ghobbs@cdpwise.net>
First post2011-07-10 22:01 -0400
Last post2011-07-14 08:55 -0400
Articles 16 on this page of 36 — 9 participants

Back to article view | Back to comp.lang.php


Contents

  Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-10 22:01 -0400
    Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-10 22:21 -0400
      Re: Restricting access to a website richard <member@newsguy.com> - 2011-07-10 22:49 -0400
        Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-11 06:38 -0400
      Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-11 16:08 -0400
        Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-11 17:29 -0400
          Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-11 18:21 -0400
            Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-12 16:27 +0200
              Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-12 11:23 -0400
              Re: Restricting access to a website Chuck Anderson <cycletourist@invalid.invalid> - 2011-07-12 10:33 -0600
                Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-12 13:04 -0400
                Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-12 15:13 -0400
                  Re: Restricting access to a website Chuck Anderson <cycletourist@invalid.invalid> - 2011-07-12 15:19 -0600
                    Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-12 19:35 -0400
          Re: Restricting access to a website Chuck Anderson <cycletourist@invalid.invalid> - 2011-07-11 17:24 -0600
            Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-11 20:38 -0400
              Re: Restricting access to a website Luuk <Luuk@invalid.lan> - 2011-07-13 21:13 +0200
                Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-13 20:43 +0100
                  Re: Restricting access to a website Luuk <Luuk@invalid.lan> - 2011-07-13 21:53 +0200
                    Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-14 00:17 +0100
                    Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-14 00:12 -0400
                  Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-13 21:56 +0200
                    Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-14 00:53 +0100
                Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-13 21:49 +0200
                  Re: Restricting access to a website Luuk <Luuk@invalid.lan> - 2011-07-13 22:12 +0200
                    Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-14 00:13 +0200
                      Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-14 00:54 +0100
                    Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-14 00:14 -0400
                Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-14 00:09 -0400
        Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-12 00:43 +0100
        Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-13 14:44 -0400
          Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-13 21:05 -0400
    Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-11 08:17 +0100
    Re: Restricting access to a website Man-wai Chang <toylet.toylet@gmail.com> - 2011-07-13 00:32 +0800
    Re: Restricting access to a website Man-wai Chang <toylet.toylet@gmail.com> - 2011-07-13 00:34 +0800
    Re: Restricting access to a website Bill B <me@privacy.net> - 2011-07-14 08:55 -0400

Page 2 of 2 — ← Prev page 1 [2]


#2556

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-07-14 00:12 -0400
Message-ID<ivlqb1$t6e$2@dont-email.me>
In reply to#2542
On 7/13/2011 3:53 PM, Luuk wrote:
> On 13-07-2011 21:43, The Natural Philosopher wrote:
>> Luuk wrote:
>>> On 12-07-2011 02:38, Jerry Stuckle wrote:
>>>> On 7/11/2011 7:24 PM, Chuck Anderson wrote:
>>>>> Jerry Stuckle wrote:
>>>>>> On 7/11/2011 4:08 PM, Graham Hobbs wrote:
>>>>>>> On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle
>>>>>>> <jstucklex@attglobal.net>  wrote:
>>>>>>>
>>>>>>>> On 7/10/2011 10:01 PM, Graham Hobbs wrote:
>>>>>>>>> Hello,
>>>>>>>>>
>>>>>>>>> I 'very laboriously' coded my index.php (close to novice level),
>>>>>>>>> for
>>>>>>>>> my website and it is up and running. It's not public yet and
>>>>>>>>> needs to
>>>>>>>>> stay that way. I need to give the address to two people who will
>>>>>>>>> help
>>>>>>>>> with my product's development .. but they could reveal the address
>>>>>>>>> anywhere, inadvertently or otherwise.
>>>>>>>>>
>>>>>>>>> If, for example, my website is www .lahdedah. com, I want to allow
>>>>>>>>> full access to these two people (and me:-)) .. others would get a
>>>>>>>>> 'Sorry, not yet available' screen. I envision hard coding their
>>>>>>>>> home
>>>>>>>>> address's into my index.php?? Am not interested in any additional
>>>>>>>>> typing by these three.
>>>>>>>>>
>>>>>>>>> Hope I've been clear. Is this feasible, easy/hard/unusual?
>>>>>>>>> Please, thanks
>>>>>>>>> Graham
>>>>>>>> There are any number of ways to do it, none of which require PHP or
>>>>>>>> any
>>>>>>>> other server-side language. Try alt.apache.configuration
>>>>>>>> (assuming, of
>>>>>>>> course, you're using Apache).
>>>>>>>>
>>>>>>>> Also, unless you are David Small of Small Expressions, you
>>>>>>>> shouldn't be
>>>>>>>> using his domain name in an example. Use www.example.com, which is
>>>>>>>> reserved for just such a purpose.
>>>>>>> ---
>>>>>>> Jerry, folks, thanks,
>>>>>>>
>>>>>>> Will check into alt.apache.configuration and apologies about
>>>>>>> lahdedah,
>>>>>>> didn't know about example.com.
>>>>>>>
>>>>>>> But I wasn't emphatic enough .. yes I would know their IP
>>>>>>> addresses so
>>>>>>> CAN I hard code them in my index.php? Yes or no would do and a PHP
>>>>>>> buzzword I might search on to get started .. I just prefer all my
>>>>>>> code
>>>>>>> in one place.
>>>>>>>
>>>>>>> .. am definitely not interested in extra keying of passwords by my
>>>>>>> two
>>>>>>> associates.
>>>>>>>
>>>>>>> Thanks,
>>>>>>> Graham
>>>>>> You definitely need alt.apache.configuration. No need to do anything
>>>>>> to your php code.
>>>>>>
>>>>> If you know the IP addrs - simply compare them to the Php global
>>>>> $SERVER['REMOTE_ADDR'].
>>>>>
>>>>>
>>>> No need to even go to that trouble.  It can all be done in the Apache
>>>> configuration with no changes to the web pages at all.
>>>>
>>>
>>> Jerry,
>>> Can you explain the REAL benefits of doing this in apache,
>>> despite the fact that this is a PHP-newsgroup?,
>>>
>>
>> Never heard of jerry explaining anything.
>>
>>> And the real drawbacks from changing a bit to his own php-code just for
>>> this case?
>>>
>>> I simply dont understand why sending him away to
>>> alt.apache.configuration is better ....
>>>
>>
>> No, its just Jerry being dumb and stubborn as usual.
>>
>> On the basis that te OP wants to play in the PHP sandpit and not the
>> Apache sandpit the optimal and more than adequate solution is to use the
>> pre-loaded variables to examine the browser remote IP address and
>> display page material contingent on that.
>>
>> Its a far more powerful and flexible way, and is the sort of thing you
>> might use to say 'Vous etes en France, Pour la version en Anglais, ici->'
>>
>> (You could aslo reconfigure your firewall to only allow physical IP
>> access from them:Sledgehammers and nuts)
>>
>>
>> As opposed to 'enter name and password to see my crap test website'
>>
>> You have to do the latter of your victims are on dynamic addresses though.
>>
>>>
>>>
>
> I understand that,
> and indeed, in this case PHP should do well,
>
> When i was a employee of a firewall-selling-company, i would probably
> reconfigure my (hardware-)firewall ;)
>
> And, last (but not least), when i did not know enough about PHP, i would
> add some rules to my apache-config.....
>

BTW - I might also suggest reconfiguring the firewall, but that won't 
work on a shared server for a number of reasons - like he doesn't have 
access to the firewall configuration and the firewall is web host blind 
- it doesn't know that the request should be restricted only for one of 
the sites on the server, and not all of them.

It's great, however, if you want to restrict *all* access to the server, 
but that's not the case in a shared environment.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#2543

FromMichael Fesser <netizen@gmx.de>
Date2011-07-13 21:56 +0200
Message-ID<5otr171ui1ahakcrqvt1m96p9q6fhogiu0@mfesser.de>
In reply to#2540
.oO(The Natural Philosopher)

>No, its just Jerry being dumb and stubborn as usual.
>
>On the basis that te OP wants to play in the PHP sandpit and not the 
>Apache sandpit the optimal and more than adequate solution is to use the 
>pre-loaded variables to examine the browser remote IP address and 
>display page material contingent on that.

Your view is as short-sighted as usual.

>Its a far more powerful and flexible way

Indeed, but it's also less efficient. The OP has to decide what's more
important in his situation. If it's just about a simple IP restriction
without a complex user management, then doing it on the Apache level is
most likely the better way.

>, and is the sort of thing you 
>might use to say 'Vous etes en France, Pour la version en Anglais, ici->'

I know French, I just can't speak it … ;-)

>(You could aslo reconfigure your firewall to only allow physical IP 
>access from them:Sledgehammers and nuts)

How's that different from altering the Apache configuration?

Micha

[toc] | [prev] | [next] | [standalone]


#2548

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2011-07-14 00:53 +0100
Message-ID<ivlb5a$lou$1@news.albasani.net>
In reply to#2543
Michael Fesser wrote:
> .oO(The Natural Philosopher)
> 
>> No, its just Jerry being dumb and stubborn as usual.
>>
>> On the basis that te OP wants to play in the PHP sandpit and not the 
>> Apache sandpit the optimal and more than adequate solution is to use the 
>> pre-loaded variables to examine the browser remote IP address and 
>> display page material contingent on that.
> 
> Your view is as short-sighted as usual.
> 
>> Its a far more powerful and flexible way
> 
> Indeed, but it's also less efficient. The OP has to decide what's more
> important in his situation. If it's just about a simple IP restriction
> without a complex user management, then doing it on the Apache level is
> most likely the better way.
> 
>> , and is the sort of thing you 
>> might use to say 'Vous etes en France, Pour la version en Anglais, ici->'
> 
> I know French, I just can't speak it … ;-)
> 
>> (You could aslo reconfigure your firewall to only allow physical IP 
>> access from them:Sledgehammers and nuts)
> 
> How's that different from altering the Apache configuration?
> 
What?
Don't you actually KNOW?

> Micha

[toc] | [prev] | [next] | [standalone]


#2541

FromMichael Fesser <netizen@gmx.de>
Date2011-07-13 21:49 +0200
Message-ID<8rsr17lirl4sssjnh1m3ms6d8ugl6imrr5@mfesser.de>
In reply to#2538
.oO(Luuk)

>On 12-07-2011 02:38, Jerry Stuckle wrote:
>> 
>> No need to even go to that trouble.  It can all be done in the Apache
>> configuration with no changes to the web pages at all.
>
>Jerry,
>Can you explain the REAL benefits of doing this in apache,
>despite the fact that this is a PHP-newsgroup?,

In this case, given the fact that limiting access can be based on static
IPs, it would be easier to implement and more efficient to do it on the
Apache level.

>And the real drawbacks from changing a bit to his own php-code just for
>this case?

IMHO it mostly depends on the way his scripts are written. In case of a
front controller, i.e. a single entry point to the website, there's not
much of a difference to the Apache way, let aside performance. But if
the website consists of individual scripts, then it might be necessary
to add the same authentication code to a whole bunch of pages.

Then there also might be things like image directories. If you want to
protect them, you either add some lines to an .htaccess file or have to
deliver all the images by a script, which makes things more complicated.

Micha

[toc] | [prev] | [next] | [standalone]


#2544

FromLuuk <Luuk@invalid.lan>
Date2011-07-13 22:12 +0200
Message-ID<4e1dfc22$0$23922$e4fe514c@news2.news.xs4all.nl>
In reply to#2541
On 13-07-2011 21:49, Michael Fesser wrote:
> .oO(Luuk)
> 
>> On 12-07-2011 02:38, Jerry Stuckle wrote:
>>>
>>> No need to even go to that trouble.  It can all be done in the Apache
>>> configuration with no changes to the web pages at all.
>>
>> Jerry,
>> Can you explain the REAL benefits of doing this in apache,
>> despite the fact that this is a PHP-newsgroup?,
> 
> In this case, given the fact that limiting access can be based on static
> IPs, it would be easier to implement and more efficient to do it on the
> Apache level.
> 
>> And the real drawbacks from changing a bit to his own php-code just for
>> this case?
> 
> IMHO it mostly depends on the way his scripts are written. In case of a
> front controller, i.e. a single entry point to the website, there's not
> much of a difference to the Apache way, let aside performance. But if
> the website consists of individual scripts, then it might be necessary
> to add the same authentication code to a whole bunch of pages.
> 
> Then there also might be things like image directories. If you want to
> protect them, you either add some lines to an .htaccess file or have to
> deliver all the images by a script, which makes things more complicated.
> 
> Micha

I know, but i wanted Jerry 'i am not a consultant-guy' to explain that
to us...

He only sends people to other newsgroups, because he does not know a
better answer. He is (almost) never giving the answer to the question
WHY the other newsgroup is a better place to ask....

-- 
Luuk

[toc] | [prev] | [next] | [standalone]


#2546

FromMichael Fesser <netizen@gmx.de>
Date2011-07-14 00:13 +0200
Message-ID<3p5s17512pf8bctt487cpdc222010um1ig@mfesser.de>
In reply to#2544
.oO(Luuk)

>I know, but i wanted Jerry 'i am not a consultant-guy' to explain that
>to us...

Sorry. ;-)

>He only sends people to other newsgroups, because he does not know a
>better answer. He is (almost) never giving the answer to the question
>WHY the other newsgroup is a better place to ask....

You really should discuss this in sci.psychology.misc …

SCNR
Micha

[toc] | [prev] | [next] | [standalone]


#2549

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2011-07-14 00:54 +0100
Message-ID<ivlb88$lou$2@news.albasani.net>
In reply to#2546
Michael Fesser wrote:
> .oO(Luuk)
> 
>> I know, but i wanted Jerry 'i am not a consultant-guy' to explain that
>> to us...
> 
> Sorry. ;-)
> 
>> He only sends people to other newsgroups, because he does not know a
>> better answer. He is (almost) never giving the answer to the question
>> WHY the other newsgroup is a better place to ask....
> 
> You really should discuss this in sci.psychology.misc …
> 
I guess the Psychology of a Right Man could keep a thread going for weeks..


But I cant hack that group title. Psychology ain't a science.


> SCNR
> Micha

[toc] | [prev] | [next] | [standalone]


#2557

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-07-14 00:14 -0400
Message-ID<ivlqfe$t6e$3@dont-email.me>
In reply to#2544
On 7/13/2011 4:12 PM, Luuk wrote:
> On 13-07-2011 21:49, Michael Fesser wrote:
>> .oO(Luuk)
>>
>>> On 12-07-2011 02:38, Jerry Stuckle wrote:
>>>>
>>>> No need to even go to that trouble.  It can all be done in the Apache
>>>> configuration with no changes to the web pages at all.
>>>
>>> Jerry,
>>> Can you explain the REAL benefits of doing this in apache,
>>> despite the fact that this is a PHP-newsgroup?,
>>
>> In this case, given the fact that limiting access can be based on static
>> IPs, it would be easier to implement and more efficient to do it on the
>> Apache level.
>>
>>> And the real drawbacks from changing a bit to his own php-code just for
>>> this case?
>>
>> IMHO it mostly depends on the way his scripts are written. In case of a
>> front controller, i.e. a single entry point to the website, there's not
>> much of a difference to the Apache way, let aside performance. But if
>> the website consists of individual scripts, then it might be necessary
>> to add the same authentication code to a whole bunch of pages.
>>
>> Then there also might be things like image directories. If you want to
>> protect them, you either add some lines to an .htaccess file or have to
>> deliver all the images by a script, which makes things more complicated.
>>
>> Micha
>
> I know, but i wanted Jerry 'i am not a consultant-guy' to explain that
> to us...
>
> He only sends people to other newsgroups, because he does not know a
> better answer. He is (almost) never giving the answer to the question
> WHY the other newsgroup is a better place to ask....
>

Wrong.  I am a consultant, and have been for over 20 years.  And I send 
people to other newsgroups when it is appropriate - as in this case.

I do also answer a lot of PHP questions in this newsgroup - as a Google 
search will easily show.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#2555

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-07-14 00:09 -0400
Message-ID<ivlq65$t6e$1@dont-email.me>
In reply to#2538
On 7/13/2011 3:13 PM, Luuk wrote:
> On 12-07-2011 02:38, Jerry Stuckle wrote:
>> On 7/11/2011 7:24 PM, Chuck Anderson wrote:
>>> Jerry Stuckle wrote:
>>>> On 7/11/2011 4:08 PM, Graham Hobbs wrote:
>>>>> On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle
>>>>> <jstucklex@attglobal.net>  wrote:
>>>>>
>>>>>> On 7/10/2011 10:01 PM, Graham Hobbs wrote:
>>>>>>> Hello,
>>>>>>>
>>>>>>> I 'very laboriously' coded my index.php (close to novice level), for
>>>>>>> my website and it is up and running. It's not public yet and needs to
>>>>>>> stay that way. I need to give the address to two people who will help
>>>>>>> with my product's development .. but they could reveal the address
>>>>>>> anywhere, inadvertently or otherwise.
>>>>>>>
>>>>>>> If, for example, my website is www .lahdedah. com, I want to allow
>>>>>>> full access to these two people (and me:-)) .. others would get a
>>>>>>> 'Sorry, not yet available' screen. I envision hard coding their home
>>>>>>> address's into my index.php?? Am not interested in any additional
>>>>>>> typing by these three.
>>>>>>>
>>>>>>> Hope I've been clear. Is this feasible, easy/hard/unusual?
>>>>>>> Please, thanks
>>>>>>> Graham
>>>>>>
>>>>>> There are any number of ways to do it, none of which require PHP or
>>>>>> any
>>>>>> other server-side language. Try alt.apache.configuration (assuming, of
>>>>>> course, you're using Apache).
>>>>>>
>>>>>> Also, unless you are David Small of Small Expressions, you
>>>>>> shouldn't be
>>>>>> using his domain name in an example. Use www.example.com, which is
>>>>>> reserved for just such a purpose.
>>>>> ---
>>>>> Jerry, folks, thanks,
>>>>>
>>>>> Will check into alt.apache.configuration and apologies about lahdedah,
>>>>> didn't know about example.com.
>>>>>
>>>>> But I wasn't emphatic enough .. yes I would know their IP addresses so
>>>>> CAN I hard code them in my index.php? Yes or no would do and a PHP
>>>>> buzzword I might search on to get started .. I just prefer all my code
>>>>> in one place.
>>>>>
>>>>> .. am definitely not interested in extra keying of passwords by my two
>>>>> associates.
>>>>>
>>>>> Thanks,
>>>>> Graham
>>>>
>>>> You definitely need alt.apache.configuration. No need to do anything
>>>> to your php code.
>>>>
>>>
>>> If you know the IP addrs - simply compare them to the Php global
>>> $SERVER['REMOTE_ADDR'].
>>>
>>>
>>
>> No need to even go to that trouble.  It can all be done in the Apache
>> configuration with no changes to the web pages at all.
>>
>
> Jerry,
> Can you explain the REAL benefits of doing this in apache,
> despite the fact that this is a PHP-newsgroup?,
>
> And the real drawbacks from changing a bit to his own php-code just for
> this case?
>
> I simply dont understand why sending him away to
> alt.apache.configuration is better ....
>
>
>

Because it can easily be done in the Apache configuration, requiring no 
changes to the page itself, and will work for all pages on his site (or 
in a specific directory).

Changing the page code requires similar changes to every page he wants 
to restrict access to, and those changes need to be later deleted from 
the code (ensuring he gets *all* pages, and doesn't make a mistake in 
deleting the code).  Simply deleting the .htaccess is all that's needed 
when he wants to open it up to everyone.  Additionally, it works for all 
web pages - not just ones coded in PHP (i.e. simple HTML pages).

Just because this is a PHP newsgroup doesn't mean the *best* answer is 
PHP code.  Many times a better solution can be found elsewhere.

And BTW - it's also slightly more efficient, because the PHP interpreter 
doesn't have to load the page and parse the code before determining the 
page should not be displayed.  Apache takes care of that long before PHP 
is ever involved.
-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#2503

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2011-07-12 00:43 +0100
Message-ID<ivg1rh$qqc$1@news.albasani.net>
In reply to#2497
Graham Hobbs wrote:
> On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle
> <jstucklex@attglobal.net> wrote:
> 
>> On 7/10/2011 10:01 PM, Graham Hobbs wrote:
>>> Hello,
>>>
>>> I 'very laboriously' coded my index.php (close to novice level), for
>>> my website and it is up and running. It's not public yet and needs to
>>> stay that way. I need to give the address to two people who will help
>>> with my product's development .. but they could reveal the address
>>> anywhere, inadvertently or otherwise.
>>>
>>> If, for example, my website is www .lahdedah. com, I want to allow
>>> full access to these two people (and me:-)) .. others would get a
>>> 'Sorry, not yet available' screen. I envision hard coding their home
>>> address's into my index.php?? Am not interested in any additional
>>> typing by these three.
>>>
>>> Hope I've been clear. Is this feasible, easy/hard/unusual?
>>> Please, thanks
>>> Graham
>> There are any number of ways to do it, none of which require PHP or any 
>> other server-side language.  Try alt.apache.configuration (assuming, of 
>> course, you're using Apache).
>>
>> Also, unless you are David Small of Small Expressions, you shouldn't be 
>> using his domain name in an example.  Use www.example.com, which is 
>> reserved for just such a purpose.
> ---
> Jerry, folks, thanks,
> 
> Will check into alt.apache.configuration and apologies about lahdedah,
> didn't know about example.com.
> 
> But I wasn't emphatic enough .. yes I would know their IP addresses so
> CAN I hard code them in my index.php? Yes or no would do and a PHP

yes.

one of the preset global variables says what the remote ip address is.

$REMOTE_ADDR  I think.


so
add this somewhere (coded in php obviously)

if not ($REMOTE_ADRR==my mates addresse)
	print fuck off
	exit
endif



> buzzword I might search on to get started .. I just prefer all my code
> in one place.
> 
> .. am definitely not interested in extra keying of passwords by my two
> associates.
> 
> Thanks,
> Graham

[toc] | [prev] | [next] | [standalone]


#2537

FromGraham Hobbs <ghobbs@cdpwise.net>
Date2011-07-13 14:44 -0400
Message-ID<mdpr17hdrt2hhvv6pn2n7hq9u6hte9lh2k@4ax.com>
In reply to#2497
Folks,
Am replying to all who contributed. I learned much, in particular,
stuff that would not have been gleaned had I referred to just the
manuals. I now have a feeling of what I can/can't do, pathways I
should follow after my associates have done with their access, in
general, a fair idea of what's going on.
Thanks to all,
Graham
A Bill B posted a while ago about some facility to collect all the
posts into one document in one shot instead of the cutting and pasting
I did for this topic - doesn't exist, right? 
'Salient bits' would be even nicer!
---
On Mon, 11 Jul 2011 16:08:53 -0400, Graham Hobbs <ghobbs@cdpwise.net>
wrote:

>On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle
><jstucklex@attglobal.net> wrote:
>
>>On 7/10/2011 10:01 PM, Graham Hobbs wrote:
>>> Hello,
>>>
>>> I 'very laboriously' coded my index.php (close to novice level), for
>>> my website and it is up and running. It's not public yet and needs to
>>> stay that way. I need to give the address to two people who will help
>>> with my product's development .. but they could reveal the address
>>> anywhere, inadvertently or otherwise.
>>>
>>> If, for example, my website is www .lahdedah. com, I want to allow
>>> full access to these two people (and me:-)) .. others would get a
>>> 'Sorry, not yet available' screen. I envision hard coding their home
>>> address's into my index.php?? Am not interested in any additional
>>> typing by these three.
>>>
>>> Hope I've been clear. Is this feasible, easy/hard/unusual?
>>> Please, thanks
>>> Graham
>>
>>There are any number of ways to do it, none of which require PHP or any 
>>other server-side language.  Try alt.apache.configuration (assuming, of 
>>course, you're using Apache).
>>
>>Also, unless you are David Small of Small Expressions, you shouldn't be 
>>using his domain name in an example.  Use www.example.com, which is 
>>reserved for just such a purpose.
>---
>Jerry, folks, thanks,
>
>Will check into alt.apache.configuration and apologies about lahdedah,
>didn't know about example.com.
>
>But I wasn't emphatic enough .. yes I would know their IP addresses so
>CAN I hard code them in my index.php? Yes or no would do and a PHP
>buzzword I might search on to get started .. I just prefer all my code
>in one place.
>
>.. am definitely not interested in extra keying of passwords by my two
>associates.
>
>Thanks,
>Graham

[toc] | [prev] | [next] | [standalone]


#2551

FromGraham Hobbs <ghobbs@cdpwise.net>
Date2011-07-13 21:05 -0400
Message-ID<0afs17hal4omd47n6claopil4uqm1haao7@4ax.com>
In reply to#2537
.. geez, I thought this was done:-)
Learned more too!+ .. is like being at a table of gurus bandering pros
and cons of circumstances (nasties aside) .. good stuff.
Thanks again
graham
---
On Wed, 13 Jul 2011 14:44:37 -0400, Graham Hobbs <ghobbs@cdpwise.net>
wrote:

>Folks,
>Am replying to all who contributed. I learned much, in particular,
>stuff that would not have been gleaned had I referred to just the
>manuals. I now have a feeling of what I can/can't do, pathways I
>should follow after my associates have done with their access, in
>general, a fair idea of what's going on.
>Thanks to all,
>Graham
>A Bill B posted a while ago about some facility to collect all the
>posts into one document in one shot instead of the cutting and pasting
>I did for this topic - doesn't exist, right? 
>'Salient bits' would be even nicer!
>---
>On Mon, 11 Jul 2011 16:08:53 -0400, Graham Hobbs <ghobbs@cdpwise.net>
>wrote:
>
>>On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle
>><jstucklex@attglobal.net> wrote:
>>
>>>On 7/10/2011 10:01 PM, Graham Hobbs wrote:
>>>> Hello,
>>>>
>>>> I 'very laboriously' coded my index.php (close to novice level), for
>>>> my website and it is up and running. It's not public yet and needs to
>>>> stay that way. I need to give the address to two people who will help
>>>> with my product's development .. but they could reveal the address
>>>> anywhere, inadvertently or otherwise.
>>>>
>>>> If, for example, my website is www .lahdedah. com, I want to allow
>>>> full access to these two people (and me:-)) .. others would get a
>>>> 'Sorry, not yet available' screen. I envision hard coding their home
>>>> address's into my index.php?? Am not interested in any additional
>>>> typing by these three.
>>>>
>>>> Hope I've been clear. Is this feasible, easy/hard/unusual?
>>>> Please, thanks
>>>> Graham
>>>
>>>There are any number of ways to do it, none of which require PHP or any 
>>>other server-side language.  Try alt.apache.configuration (assuming, of 
>>>course, you're using Apache).
>>>
>>>Also, unless you are David Small of Small Expressions, you shouldn't be 
>>>using his domain name in an example.  Use www.example.com, which is 
>>>reserved for just such a purpose.
>>---
>>Jerry, folks, thanks,
>>
>>Will check into alt.apache.configuration and apologies about lahdedah,
>>didn't know about example.com.
>>
>>But I wasn't emphatic enough .. yes I would know their IP addresses so
>>CAN I hard code them in my index.php? Yes or no would do and a PHP
>>buzzword I might search on to get started .. I just prefer all my code
>>in one place.
>>
>>.. am definitely not interested in extra keying of passwords by my two
>>associates.
>>
>>Thanks,
>>Graham

[toc] | [prev] | [next] | [standalone]


#2486

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2011-07-11 08:17 +0100
Message-ID<ive81s$cqa$1@news.albasani.net>
In reply to#2482
Graham Hobbs wrote:
> Hello,
> 
> I 'very laboriously' coded my index.php (close to novice level), for
> my website and it is up and running. It's not public yet and needs to
> stay that way. I need to give the address to two people who will help
> with my product's development .. but they could reveal the address
> anywhere, inadvertently or otherwise.
> 
> If, for example, my website is www .lahdedah. com, I want to allow
> full access to these two people (and me:-)) .. others would get a
> 'Sorry, not yet available' screen. I envision hard coding their home
> address's into my index.php?? Am not interested in any additional
> typing by these three.
> 
> Hope I've been clear. Is this feasible, easy/hard/unusual?
> Please, thanks
> Graham
If they are on fixed IP, its a snap to respond differently to them.

If they are on dynamic addresses the quick hack is to drop a password 
protection file (.htaccess typically) in the server root directory and 
create usernames and passwords for them.

But that's an apache setup issue, and off topic here.

[toc] | [prev] | [next] | [standalone]


#2511

FromMan-wai Chang <toylet.toylet@gmail.com>
Date2011-07-13 00:32 +0800
Message-ID<ivhsua$4pj$1@dont-email.me>
In reply to#2482
> If, for example, my website is www .lahdedah. com, I want to allow
> full access to these two people (and me:-)) .. others would get a
> 'Sorry, not yet available' screen. I envision hard coding their home
> address's into my index.php?? Am not interested in any additional
> typing by these three.

Why not just use http_access passwd?


-- 
   @~@   You have the right to remain silent.
  / v \  Simplicity is Beauty! May the Force and farces be with you!
/( _ )\ (x86_64 Ubuntu 9.10)  Linux 2.6.39.3
   ^ ^   00:27:01 up 5:56 0 users load average: 1.40 1.11 1.08
不借貸! 不詐騙! 不援交! 不打交! 不打劫! 不自殺! 請考慮綜援 (CSSA):
http://www.swd.gov.hk/tc/index/site_pubsvc/page_socsecu/sub_addressesa

[toc] | [prev] | [next] | [standalone]


#2513

FromMan-wai Chang <toylet.toylet@gmail.com>
Date2011-07-13 00:34 +0800
Message-ID<ivht2r$4pj$2@dont-email.me>
In reply to#2482
> If, for example, my website is www .lahdedah. com, I want to allow
> full access to these two people (and me:-)) .. others would get a
> 'Sorry, not yet available' screen. I envision hard coding their home
> address's into my index.php?? Am not interested in any additional
> typing by these three.

Another solution:

1. set your apache to access only 127.0.0.1 access
2. install and configure openssh server
3. remote user login your server and access apache via tunneling

-- 
   @~@   You have the right to remain silent.
  / v \  Simplicity is Beauty! May the Force and farces be with you!
/( _ )\ (x86_64 Ubuntu 9.10)  Linux 2.6.39.3
   ^ ^   00:32:02 up 6:01 0 users load average: 1.02 1.14 1.12
不借貸! 不詐騙! 不援交! 不打交! 不打劫! 不自殺! 請考慮綜援 (CSSA):
http://www.swd.gov.hk/tc/index/site_pubsvc/page_socsecu/sub_addressesa

[toc] | [prev] | [next] | [standalone]


#2558

FromBill B <me@privacy.net>
Date2011-07-14 08:55 -0400
Message-ID<ivmov2$m9l$2@dont-email.me>
In reply to#2482
On 7/10/2011 10:01 PM, Graham Hobbs wrote:
> Hello,
>
> I 'very laboriously' coded my index.php (close to novice level), for
> my website and it is up and running. It's not public yet and needs to
> stay that way. I need to give the address to two people who will help
> with my product's development .. but they could reveal the address
> anywhere, inadvertently or otherwise.
>
> If, for example, my website is www .lahdedah. com, I want to allow
> full access to these two people (and me:-)) .. others would get a
> 'Sorry, not yet available' screen. I envision hard coding their home
> address's into my index.php?? Am not interested in any additional
> typing by these three.

Use a login routine but do not make registrations possible. Manually 
place the user info for the three people that can have access.If someone 
using any other username tries to log in they will be blocked.

Bill B

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.lang.php


csiph-web