Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #2482 > unrolled thread
| Started by | Graham Hobbs <ghobbs@cdpwise.net> |
|---|---|
| First post | 2011-07-10 22:01 -0400 |
| Last post | 2011-07-14 08:55 -0400 |
| Articles | 16 on this page of 36 — 9 participants |
Back to article view | Back to comp.lang.php
Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-10 22:01 -0400
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-10 22:21 -0400
Re: Restricting access to a website richard <member@newsguy.com> - 2011-07-10 22:49 -0400
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-11 06:38 -0400
Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-11 16:08 -0400
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-11 17:29 -0400
Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-11 18:21 -0400
Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-12 16:27 +0200
Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-12 11:23 -0400
Re: Restricting access to a website Chuck Anderson <cycletourist@invalid.invalid> - 2011-07-12 10:33 -0600
Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-12 13:04 -0400
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-12 15:13 -0400
Re: Restricting access to a website Chuck Anderson <cycletourist@invalid.invalid> - 2011-07-12 15:19 -0600
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-12 19:35 -0400
Re: Restricting access to a website Chuck Anderson <cycletourist@invalid.invalid> - 2011-07-11 17:24 -0600
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-11 20:38 -0400
Re: Restricting access to a website Luuk <Luuk@invalid.lan> - 2011-07-13 21:13 +0200
Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-13 20:43 +0100
Re: Restricting access to a website Luuk <Luuk@invalid.lan> - 2011-07-13 21:53 +0200
Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-14 00:17 +0100
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-14 00:12 -0400
Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-13 21:56 +0200
Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-14 00:53 +0100
Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-13 21:49 +0200
Re: Restricting access to a website Luuk <Luuk@invalid.lan> - 2011-07-13 22:12 +0200
Re: Restricting access to a website Michael Fesser <netizen@gmx.de> - 2011-07-14 00:13 +0200
Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-14 00:54 +0100
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-14 00:14 -0400
Re: Restricting access to a website Jerry Stuckle <jstucklex@attglobal.net> - 2011-07-14 00:09 -0400
Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-12 00:43 +0100
Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-13 14:44 -0400
Re: Restricting access to a website Graham Hobbs <ghobbs@cdpwise.net> - 2011-07-13 21:05 -0400
Re: Restricting access to a website The Natural Philosopher <tnp@invalid.invalid> - 2011-07-11 08:17 +0100
Re: Restricting access to a website Man-wai Chang <toylet.toylet@gmail.com> - 2011-07-13 00:32 +0800
Re: Restricting access to a website Man-wai Chang <toylet.toylet@gmail.com> - 2011-07-13 00:34 +0800
Re: Restricting access to a website Bill B <me@privacy.net> - 2011-07-14 08:55 -0400
Page 2 of 2 — ← Prev page 1 [2]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-07-14 00:12 -0400 |
| Message-ID | <ivlqb1$t6e$2@dont-email.me> |
| In reply to | #2542 |
On 7/13/2011 3:53 PM, Luuk wrote: > On 13-07-2011 21:43, The Natural Philosopher wrote: >> Luuk wrote: >>> On 12-07-2011 02:38, Jerry Stuckle wrote: >>>> On 7/11/2011 7:24 PM, Chuck Anderson wrote: >>>>> Jerry Stuckle wrote: >>>>>> On 7/11/2011 4:08 PM, Graham Hobbs wrote: >>>>>>> On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle >>>>>>> <jstucklex@attglobal.net> wrote: >>>>>>> >>>>>>>> On 7/10/2011 10:01 PM, Graham Hobbs wrote: >>>>>>>>> Hello, >>>>>>>>> >>>>>>>>> I 'very laboriously' coded my index.php (close to novice level), >>>>>>>>> for >>>>>>>>> my website and it is up and running. It's not public yet and >>>>>>>>> needs to >>>>>>>>> stay that way. I need to give the address to two people who will >>>>>>>>> help >>>>>>>>> with my product's development .. but they could reveal the address >>>>>>>>> anywhere, inadvertently or otherwise. >>>>>>>>> >>>>>>>>> If, for example, my website is www .lahdedah. com, I want to allow >>>>>>>>> full access to these two people (and me:-)) .. others would get a >>>>>>>>> 'Sorry, not yet available' screen. I envision hard coding their >>>>>>>>> home >>>>>>>>> address's into my index.php?? Am not interested in any additional >>>>>>>>> typing by these three. >>>>>>>>> >>>>>>>>> Hope I've been clear. Is this feasible, easy/hard/unusual? >>>>>>>>> Please, thanks >>>>>>>>> Graham >>>>>>>> There are any number of ways to do it, none of which require PHP or >>>>>>>> any >>>>>>>> other server-side language. Try alt.apache.configuration >>>>>>>> (assuming, of >>>>>>>> course, you're using Apache). >>>>>>>> >>>>>>>> Also, unless you are David Small of Small Expressions, you >>>>>>>> shouldn't be >>>>>>>> using his domain name in an example. Use www.example.com, which is >>>>>>>> reserved for just such a purpose. >>>>>>> --- >>>>>>> Jerry, folks, thanks, >>>>>>> >>>>>>> Will check into alt.apache.configuration and apologies about >>>>>>> lahdedah, >>>>>>> didn't know about example.com. >>>>>>> >>>>>>> But I wasn't emphatic enough .. yes I would know their IP >>>>>>> addresses so >>>>>>> CAN I hard code them in my index.php? Yes or no would do and a PHP >>>>>>> buzzword I might search on to get started .. I just prefer all my >>>>>>> code >>>>>>> in one place. >>>>>>> >>>>>>> .. am definitely not interested in extra keying of passwords by my >>>>>>> two >>>>>>> associates. >>>>>>> >>>>>>> Thanks, >>>>>>> Graham >>>>>> You definitely need alt.apache.configuration. No need to do anything >>>>>> to your php code. >>>>>> >>>>> If you know the IP addrs - simply compare them to the Php global >>>>> $SERVER['REMOTE_ADDR']. >>>>> >>>>> >>>> No need to even go to that trouble. It can all be done in the Apache >>>> configuration with no changes to the web pages at all. >>>> >>> >>> Jerry, >>> Can you explain the REAL benefits of doing this in apache, >>> despite the fact that this is a PHP-newsgroup?, >>> >> >> Never heard of jerry explaining anything. >> >>> And the real drawbacks from changing a bit to his own php-code just for >>> this case? >>> >>> I simply dont understand why sending him away to >>> alt.apache.configuration is better .... >>> >> >> No, its just Jerry being dumb and stubborn as usual. >> >> On the basis that te OP wants to play in the PHP sandpit and not the >> Apache sandpit the optimal and more than adequate solution is to use the >> pre-loaded variables to examine the browser remote IP address and >> display page material contingent on that. >> >> Its a far more powerful and flexible way, and is the sort of thing you >> might use to say 'Vous etes en France, Pour la version en Anglais, ici->' >> >> (You could aslo reconfigure your firewall to only allow physical IP >> access from them:Sledgehammers and nuts) >> >> >> As opposed to 'enter name and password to see my crap test website' >> >> You have to do the latter of your victims are on dynamic addresses though. >> >>> >>> > > I understand that, > and indeed, in this case PHP should do well, > > When i was a employee of a firewall-selling-company, i would probably > reconfigure my (hardware-)firewall ;) > > And, last (but not least), when i did not know enough about PHP, i would > add some rules to my apache-config..... > BTW - I might also suggest reconfiguring the firewall, but that won't work on a shared server for a number of reasons - like he doesn't have access to the firewall configuration and the firewall is web host blind - it doesn't know that the request should be restricted only for one of the sites on the server, and not all of them. It's great, however, if you want to restrict *all* access to the server, but that's not the case in a shared environment. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Michael Fesser <netizen@gmx.de> |
|---|---|
| Date | 2011-07-13 21:56 +0200 |
| Message-ID | <5otr171ui1ahakcrqvt1m96p9q6fhogiu0@mfesser.de> |
| In reply to | #2540 |
.oO(The Natural Philosopher) >No, its just Jerry being dumb and stubborn as usual. > >On the basis that te OP wants to play in the PHP sandpit and not the >Apache sandpit the optimal and more than adequate solution is to use the >pre-loaded variables to examine the browser remote IP address and >display page material contingent on that. Your view is as short-sighted as usual. >Its a far more powerful and flexible way Indeed, but it's also less efficient. The OP has to decide what's more important in his situation. If it's just about a simple IP restriction without a complex user management, then doing it on the Apache level is most likely the better way. >, and is the sort of thing you >might use to say 'Vous etes en France, Pour la version en Anglais, ici->' I know French, I just can't speak it … ;-) >(You could aslo reconfigure your firewall to only allow physical IP >access from them:Sledgehammers and nuts) How's that different from altering the Apache configuration? Micha
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2011-07-14 00:53 +0100 |
| Message-ID | <ivlb5a$lou$1@news.albasani.net> |
| In reply to | #2543 |
Michael Fesser wrote: > .oO(The Natural Philosopher) > >> No, its just Jerry being dumb and stubborn as usual. >> >> On the basis that te OP wants to play in the PHP sandpit and not the >> Apache sandpit the optimal and more than adequate solution is to use the >> pre-loaded variables to examine the browser remote IP address and >> display page material contingent on that. > > Your view is as short-sighted as usual. > >> Its a far more powerful and flexible way > > Indeed, but it's also less efficient. The OP has to decide what's more > important in his situation. If it's just about a simple IP restriction > without a complex user management, then doing it on the Apache level is > most likely the better way. > >> , and is the sort of thing you >> might use to say 'Vous etes en France, Pour la version en Anglais, ici->' > > I know French, I just can't speak it … ;-) > >> (You could aslo reconfigure your firewall to only allow physical IP >> access from them:Sledgehammers and nuts) > > How's that different from altering the Apache configuration? > What? Don't you actually KNOW? > Micha
[toc] | [prev] | [next] | [standalone]
| From | Michael Fesser <netizen@gmx.de> |
|---|---|
| Date | 2011-07-13 21:49 +0200 |
| Message-ID | <8rsr17lirl4sssjnh1m3ms6d8ugl6imrr5@mfesser.de> |
| In reply to | #2538 |
.oO(Luuk) >On 12-07-2011 02:38, Jerry Stuckle wrote: >> >> No need to even go to that trouble. It can all be done in the Apache >> configuration with no changes to the web pages at all. > >Jerry, >Can you explain the REAL benefits of doing this in apache, >despite the fact that this is a PHP-newsgroup?, In this case, given the fact that limiting access can be based on static IPs, it would be easier to implement and more efficient to do it on the Apache level. >And the real drawbacks from changing a bit to his own php-code just for >this case? IMHO it mostly depends on the way his scripts are written. In case of a front controller, i.e. a single entry point to the website, there's not much of a difference to the Apache way, let aside performance. But if the website consists of individual scripts, then it might be necessary to add the same authentication code to a whole bunch of pages. Then there also might be things like image directories. If you want to protect them, you either add some lines to an .htaccess file or have to deliver all the images by a script, which makes things more complicated. Micha
[toc] | [prev] | [next] | [standalone]
| From | Luuk <Luuk@invalid.lan> |
|---|---|
| Date | 2011-07-13 22:12 +0200 |
| Message-ID | <4e1dfc22$0$23922$e4fe514c@news2.news.xs4all.nl> |
| In reply to | #2541 |
On 13-07-2011 21:49, Michael Fesser wrote: > .oO(Luuk) > >> On 12-07-2011 02:38, Jerry Stuckle wrote: >>> >>> No need to even go to that trouble. It can all be done in the Apache >>> configuration with no changes to the web pages at all. >> >> Jerry, >> Can you explain the REAL benefits of doing this in apache, >> despite the fact that this is a PHP-newsgroup?, > > In this case, given the fact that limiting access can be based on static > IPs, it would be easier to implement and more efficient to do it on the > Apache level. > >> And the real drawbacks from changing a bit to his own php-code just for >> this case? > > IMHO it mostly depends on the way his scripts are written. In case of a > front controller, i.e. a single entry point to the website, there's not > much of a difference to the Apache way, let aside performance. But if > the website consists of individual scripts, then it might be necessary > to add the same authentication code to a whole bunch of pages. > > Then there also might be things like image directories. If you want to > protect them, you either add some lines to an .htaccess file or have to > deliver all the images by a script, which makes things more complicated. > > Micha I know, but i wanted Jerry 'i am not a consultant-guy' to explain that to us... He only sends people to other newsgroups, because he does not know a better answer. He is (almost) never giving the answer to the question WHY the other newsgroup is a better place to ask.... -- Luuk
[toc] | [prev] | [next] | [standalone]
| From | Michael Fesser <netizen@gmx.de> |
|---|---|
| Date | 2011-07-14 00:13 +0200 |
| Message-ID | <3p5s17512pf8bctt487cpdc222010um1ig@mfesser.de> |
| In reply to | #2544 |
.oO(Luuk) >I know, but i wanted Jerry 'i am not a consultant-guy' to explain that >to us... Sorry. ;-) >He only sends people to other newsgroups, because he does not know a >better answer. He is (almost) never giving the answer to the question >WHY the other newsgroup is a better place to ask.... You really should discuss this in sci.psychology.misc … SCNR Micha
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2011-07-14 00:54 +0100 |
| Message-ID | <ivlb88$lou$2@news.albasani.net> |
| In reply to | #2546 |
Michael Fesser wrote: > .oO(Luuk) > >> I know, but i wanted Jerry 'i am not a consultant-guy' to explain that >> to us... > > Sorry. ;-) > >> He only sends people to other newsgroups, because he does not know a >> better answer. He is (almost) never giving the answer to the question >> WHY the other newsgroup is a better place to ask.... > > You really should discuss this in sci.psychology.misc … > I guess the Psychology of a Right Man could keep a thread going for weeks.. But I cant hack that group title. Psychology ain't a science. > SCNR > Micha
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-07-14 00:14 -0400 |
| Message-ID | <ivlqfe$t6e$3@dont-email.me> |
| In reply to | #2544 |
On 7/13/2011 4:12 PM, Luuk wrote: > On 13-07-2011 21:49, Michael Fesser wrote: >> .oO(Luuk) >> >>> On 12-07-2011 02:38, Jerry Stuckle wrote: >>>> >>>> No need to even go to that trouble. It can all be done in the Apache >>>> configuration with no changes to the web pages at all. >>> >>> Jerry, >>> Can you explain the REAL benefits of doing this in apache, >>> despite the fact that this is a PHP-newsgroup?, >> >> In this case, given the fact that limiting access can be based on static >> IPs, it would be easier to implement and more efficient to do it on the >> Apache level. >> >>> And the real drawbacks from changing a bit to his own php-code just for >>> this case? >> >> IMHO it mostly depends on the way his scripts are written. In case of a >> front controller, i.e. a single entry point to the website, there's not >> much of a difference to the Apache way, let aside performance. But if >> the website consists of individual scripts, then it might be necessary >> to add the same authentication code to a whole bunch of pages. >> >> Then there also might be things like image directories. If you want to >> protect them, you either add some lines to an .htaccess file or have to >> deliver all the images by a script, which makes things more complicated. >> >> Micha > > I know, but i wanted Jerry 'i am not a consultant-guy' to explain that > to us... > > He only sends people to other newsgroups, because he does not know a > better answer. He is (almost) never giving the answer to the question > WHY the other newsgroup is a better place to ask.... > Wrong. I am a consultant, and have been for over 20 years. And I send people to other newsgroups when it is appropriate - as in this case. I do also answer a lot of PHP questions in this newsgroup - as a Google search will easily show. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2011-07-14 00:09 -0400 |
| Message-ID | <ivlq65$t6e$1@dont-email.me> |
| In reply to | #2538 |
On 7/13/2011 3:13 PM, Luuk wrote: > On 12-07-2011 02:38, Jerry Stuckle wrote: >> On 7/11/2011 7:24 PM, Chuck Anderson wrote: >>> Jerry Stuckle wrote: >>>> On 7/11/2011 4:08 PM, Graham Hobbs wrote: >>>>> On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle >>>>> <jstucklex@attglobal.net> wrote: >>>>> >>>>>> On 7/10/2011 10:01 PM, Graham Hobbs wrote: >>>>>>> Hello, >>>>>>> >>>>>>> I 'very laboriously' coded my index.php (close to novice level), for >>>>>>> my website and it is up and running. It's not public yet and needs to >>>>>>> stay that way. I need to give the address to two people who will help >>>>>>> with my product's development .. but they could reveal the address >>>>>>> anywhere, inadvertently or otherwise. >>>>>>> >>>>>>> If, for example, my website is www .lahdedah. com, I want to allow >>>>>>> full access to these two people (and me:-)) .. others would get a >>>>>>> 'Sorry, not yet available' screen. I envision hard coding their home >>>>>>> address's into my index.php?? Am not interested in any additional >>>>>>> typing by these three. >>>>>>> >>>>>>> Hope I've been clear. Is this feasible, easy/hard/unusual? >>>>>>> Please, thanks >>>>>>> Graham >>>>>> >>>>>> There are any number of ways to do it, none of which require PHP or >>>>>> any >>>>>> other server-side language. Try alt.apache.configuration (assuming, of >>>>>> course, you're using Apache). >>>>>> >>>>>> Also, unless you are David Small of Small Expressions, you >>>>>> shouldn't be >>>>>> using his domain name in an example. Use www.example.com, which is >>>>>> reserved for just such a purpose. >>>>> --- >>>>> Jerry, folks, thanks, >>>>> >>>>> Will check into alt.apache.configuration and apologies about lahdedah, >>>>> didn't know about example.com. >>>>> >>>>> But I wasn't emphatic enough .. yes I would know their IP addresses so >>>>> CAN I hard code them in my index.php? Yes or no would do and a PHP >>>>> buzzword I might search on to get started .. I just prefer all my code >>>>> in one place. >>>>> >>>>> .. am definitely not interested in extra keying of passwords by my two >>>>> associates. >>>>> >>>>> Thanks, >>>>> Graham >>>> >>>> You definitely need alt.apache.configuration. No need to do anything >>>> to your php code. >>>> >>> >>> If you know the IP addrs - simply compare them to the Php global >>> $SERVER['REMOTE_ADDR']. >>> >>> >> >> No need to even go to that trouble. It can all be done in the Apache >> configuration with no changes to the web pages at all. >> > > Jerry, > Can you explain the REAL benefits of doing this in apache, > despite the fact that this is a PHP-newsgroup?, > > And the real drawbacks from changing a bit to his own php-code just for > this case? > > I simply dont understand why sending him away to > alt.apache.configuration is better .... > > > Because it can easily be done in the Apache configuration, requiring no changes to the page itself, and will work for all pages on his site (or in a specific directory). Changing the page code requires similar changes to every page he wants to restrict access to, and those changes need to be later deleted from the code (ensuring he gets *all* pages, and doesn't make a mistake in deleting the code). Simply deleting the .htaccess is all that's needed when he wants to open it up to everyone. Additionally, it works for all web pages - not just ones coded in PHP (i.e. simple HTML pages). Just because this is a PHP newsgroup doesn't mean the *best* answer is PHP code. Many times a better solution can be found elsewhere. And BTW - it's also slightly more efficient, because the PHP interpreter doesn't have to load the page and parse the code before determining the page should not be displayed. Apache takes care of that long before PHP is ever involved. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2011-07-12 00:43 +0100 |
| Message-ID | <ivg1rh$qqc$1@news.albasani.net> |
| In reply to | #2497 |
Graham Hobbs wrote: > On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle > <jstucklex@attglobal.net> wrote: > >> On 7/10/2011 10:01 PM, Graham Hobbs wrote: >>> Hello, >>> >>> I 'very laboriously' coded my index.php (close to novice level), for >>> my website and it is up and running. It's not public yet and needs to >>> stay that way. I need to give the address to two people who will help >>> with my product's development .. but they could reveal the address >>> anywhere, inadvertently or otherwise. >>> >>> If, for example, my website is www .lahdedah. com, I want to allow >>> full access to these two people (and me:-)) .. others would get a >>> 'Sorry, not yet available' screen. I envision hard coding their home >>> address's into my index.php?? Am not interested in any additional >>> typing by these three. >>> >>> Hope I've been clear. Is this feasible, easy/hard/unusual? >>> Please, thanks >>> Graham >> There are any number of ways to do it, none of which require PHP or any >> other server-side language. Try alt.apache.configuration (assuming, of >> course, you're using Apache). >> >> Also, unless you are David Small of Small Expressions, you shouldn't be >> using his domain name in an example. Use www.example.com, which is >> reserved for just such a purpose. > --- > Jerry, folks, thanks, > > Will check into alt.apache.configuration and apologies about lahdedah, > didn't know about example.com. > > But I wasn't emphatic enough .. yes I would know their IP addresses so > CAN I hard code them in my index.php? Yes or no would do and a PHP yes. one of the preset global variables says what the remote ip address is. $REMOTE_ADDR I think. so add this somewhere (coded in php obviously) if not ($REMOTE_ADRR==my mates addresse) print fuck off exit endif > buzzword I might search on to get started .. I just prefer all my code > in one place. > > .. am definitely not interested in extra keying of passwords by my two > associates. > > Thanks, > Graham
[toc] | [prev] | [next] | [standalone]
| From | Graham Hobbs <ghobbs@cdpwise.net> |
|---|---|
| Date | 2011-07-13 14:44 -0400 |
| Message-ID | <mdpr17hdrt2hhvv6pn2n7hq9u6hte9lh2k@4ax.com> |
| In reply to | #2497 |
Folks, Am replying to all who contributed. I learned much, in particular, stuff that would not have been gleaned had I referred to just the manuals. I now have a feeling of what I can/can't do, pathways I should follow after my associates have done with their access, in general, a fair idea of what's going on. Thanks to all, Graham A Bill B posted a while ago about some facility to collect all the posts into one document in one shot instead of the cutting and pasting I did for this topic - doesn't exist, right? 'Salient bits' would be even nicer! --- On Mon, 11 Jul 2011 16:08:53 -0400, Graham Hobbs <ghobbs@cdpwise.net> wrote: >On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle ><jstucklex@attglobal.net> wrote: > >>On 7/10/2011 10:01 PM, Graham Hobbs wrote: >>> Hello, >>> >>> I 'very laboriously' coded my index.php (close to novice level), for >>> my website and it is up and running. It's not public yet and needs to >>> stay that way. I need to give the address to two people who will help >>> with my product's development .. but they could reveal the address >>> anywhere, inadvertently or otherwise. >>> >>> If, for example, my website is www .lahdedah. com, I want to allow >>> full access to these two people (and me:-)) .. others would get a >>> 'Sorry, not yet available' screen. I envision hard coding their home >>> address's into my index.php?? Am not interested in any additional >>> typing by these three. >>> >>> Hope I've been clear. Is this feasible, easy/hard/unusual? >>> Please, thanks >>> Graham >> >>There are any number of ways to do it, none of which require PHP or any >>other server-side language. Try alt.apache.configuration (assuming, of >>course, you're using Apache). >> >>Also, unless you are David Small of Small Expressions, you shouldn't be >>using his domain name in an example. Use www.example.com, which is >>reserved for just such a purpose. >--- >Jerry, folks, thanks, > >Will check into alt.apache.configuration and apologies about lahdedah, >didn't know about example.com. > >But I wasn't emphatic enough .. yes I would know their IP addresses so >CAN I hard code them in my index.php? Yes or no would do and a PHP >buzzword I might search on to get started .. I just prefer all my code >in one place. > >.. am definitely not interested in extra keying of passwords by my two >associates. > >Thanks, >Graham
[toc] | [prev] | [next] | [standalone]
| From | Graham Hobbs <ghobbs@cdpwise.net> |
|---|---|
| Date | 2011-07-13 21:05 -0400 |
| Message-ID | <0afs17hal4omd47n6claopil4uqm1haao7@4ax.com> |
| In reply to | #2537 |
.. geez, I thought this was done:-) Learned more too!+ .. is like being at a table of gurus bandering pros and cons of circumstances (nasties aside) .. good stuff. Thanks again graham --- On Wed, 13 Jul 2011 14:44:37 -0400, Graham Hobbs <ghobbs@cdpwise.net> wrote: >Folks, >Am replying to all who contributed. I learned much, in particular, >stuff that would not have been gleaned had I referred to just the >manuals. I now have a feeling of what I can/can't do, pathways I >should follow after my associates have done with their access, in >general, a fair idea of what's going on. >Thanks to all, >Graham >A Bill B posted a while ago about some facility to collect all the >posts into one document in one shot instead of the cutting and pasting >I did for this topic - doesn't exist, right? >'Salient bits' would be even nicer! >--- >On Mon, 11 Jul 2011 16:08:53 -0400, Graham Hobbs <ghobbs@cdpwise.net> >wrote: > >>On Sun, 10 Jul 2011 22:21:41 -0400, Jerry Stuckle >><jstucklex@attglobal.net> wrote: >> >>>On 7/10/2011 10:01 PM, Graham Hobbs wrote: >>>> Hello, >>>> >>>> I 'very laboriously' coded my index.php (close to novice level), for >>>> my website and it is up and running. It's not public yet and needs to >>>> stay that way. I need to give the address to two people who will help >>>> with my product's development .. but they could reveal the address >>>> anywhere, inadvertently or otherwise. >>>> >>>> If, for example, my website is www .lahdedah. com, I want to allow >>>> full access to these two people (and me:-)) .. others would get a >>>> 'Sorry, not yet available' screen. I envision hard coding their home >>>> address's into my index.php?? Am not interested in any additional >>>> typing by these three. >>>> >>>> Hope I've been clear. Is this feasible, easy/hard/unusual? >>>> Please, thanks >>>> Graham >>> >>>There are any number of ways to do it, none of which require PHP or any >>>other server-side language. Try alt.apache.configuration (assuming, of >>>course, you're using Apache). >>> >>>Also, unless you are David Small of Small Expressions, you shouldn't be >>>using his domain name in an example. Use www.example.com, which is >>>reserved for just such a purpose. >>--- >>Jerry, folks, thanks, >> >>Will check into alt.apache.configuration and apologies about lahdedah, >>didn't know about example.com. >> >>But I wasn't emphatic enough .. yes I would know their IP addresses so >>CAN I hard code them in my index.php? Yes or no would do and a PHP >>buzzword I might search on to get started .. I just prefer all my code >>in one place. >> >>.. am definitely not interested in extra keying of passwords by my two >>associates. >> >>Thanks, >>Graham
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2011-07-11 08:17 +0100 |
| Message-ID | <ive81s$cqa$1@news.albasani.net> |
| In reply to | #2482 |
Graham Hobbs wrote: > Hello, > > I 'very laboriously' coded my index.php (close to novice level), for > my website and it is up and running. It's not public yet and needs to > stay that way. I need to give the address to two people who will help > with my product's development .. but they could reveal the address > anywhere, inadvertently or otherwise. > > If, for example, my website is www .lahdedah. com, I want to allow > full access to these two people (and me:-)) .. others would get a > 'Sorry, not yet available' screen. I envision hard coding their home > address's into my index.php?? Am not interested in any additional > typing by these three. > > Hope I've been clear. Is this feasible, easy/hard/unusual? > Please, thanks > Graham If they are on fixed IP, its a snap to respond differently to them. If they are on dynamic addresses the quick hack is to drop a password protection file (.htaccess typically) in the server root directory and create usernames and passwords for them. But that's an apache setup issue, and off topic here.
[toc] | [prev] | [next] | [standalone]
| From | Man-wai Chang <toylet.toylet@gmail.com> |
|---|---|
| Date | 2011-07-13 00:32 +0800 |
| Message-ID | <ivhsua$4pj$1@dont-email.me> |
| In reply to | #2482 |
> If, for example, my website is www .lahdedah. com, I want to allow > full access to these two people (and me:-)) .. others would get a > 'Sorry, not yet available' screen. I envision hard coding their home > address's into my index.php?? Am not interested in any additional > typing by these three. Why not just use http_access passwd? -- @~@ You have the right to remain silent. / v \ Simplicity is Beauty! May the Force and farces be with you! /( _ )\ (x86_64 Ubuntu 9.10) Linux 2.6.39.3 ^ ^ 00:27:01 up 5:56 0 users load average: 1.40 1.11 1.08 不借貸! 不詐騙! 不援交! 不打交! 不打劫! 不自殺! 請考慮綜援 (CSSA): http://www.swd.gov.hk/tc/index/site_pubsvc/page_socsecu/sub_addressesa
[toc] | [prev] | [next] | [standalone]
| From | Man-wai Chang <toylet.toylet@gmail.com> |
|---|---|
| Date | 2011-07-13 00:34 +0800 |
| Message-ID | <ivht2r$4pj$2@dont-email.me> |
| In reply to | #2482 |
> If, for example, my website is www .lahdedah. com, I want to allow > full access to these two people (and me:-)) .. others would get a > 'Sorry, not yet available' screen. I envision hard coding their home > address's into my index.php?? Am not interested in any additional > typing by these three. Another solution: 1. set your apache to access only 127.0.0.1 access 2. install and configure openssh server 3. remote user login your server and access apache via tunneling -- @~@ You have the right to remain silent. / v \ Simplicity is Beauty! May the Force and farces be with you! /( _ )\ (x86_64 Ubuntu 9.10) Linux 2.6.39.3 ^ ^ 00:32:02 up 6:01 0 users load average: 1.02 1.14 1.12 不借貸! 不詐騙! 不援交! 不打交! 不打劫! 不自殺! 請考慮綜援 (CSSA): http://www.swd.gov.hk/tc/index/site_pubsvc/page_socsecu/sub_addressesa
[toc] | [prev] | [next] | [standalone]
| From | Bill B <me@privacy.net> |
|---|---|
| Date | 2011-07-14 08:55 -0400 |
| Message-ID | <ivmov2$m9l$2@dont-email.me> |
| In reply to | #2482 |
On 7/10/2011 10:01 PM, Graham Hobbs wrote: > Hello, > > I 'very laboriously' coded my index.php (close to novice level), for > my website and it is up and running. It's not public yet and needs to > stay that way. I need to give the address to two people who will help > with my product's development .. but they could reveal the address > anywhere, inadvertently or otherwise. > > If, for example, my website is www .lahdedah. com, I want to allow > full access to these two people (and me:-)) .. others would get a > 'Sorry, not yet available' screen. I envision hard coding their home > address's into my index.php?? Am not interested in any additional > typing by these three. Use a login routine but do not make registrations possible. Manually place the user info for the three people that can have access.If someone using any other username tries to log in they will be blocked. Bill B
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.lang.php
csiph-web