WebApp Sec mailing list archives

Re: Securing file access


From: "Saphyr" <saphyr () infomaniak ch>
Date: Tue, 28 Sep 2004 08:15:28 +0200

guess a file name to download).  In order to access the files, the database
would link a file to a unique id, so a page that validates the user would
then give access to the file stored outside of the www on the server.  Now,
this is where the real question lies.  How is this possible since the files
are not in a www accessible path, since a mere link to a file won't due.
Any thoughts would be welcome.

Hi there.

According to your files sizes, could you consider using binary fields in your
database ?

.antoine




------------oOoo---Ôô----ooOo---------------------------
Antonio FONTES    (well, me, actually)
http://www.nxtg.net/saphyr/  (tout et rien en français)
http://www.nxtg.net/is/ (blog - développeur web)
E-mail: prenom.nom () mondomaine net
-------------------------------------------------------------



Current thread: