php - Image security and linux file/directory permissions -
in php app allowing users upload photos. upon user upload, metadata stored in db , images stored in directory on linux server. want these images viewable when called through view can verify correct party viewing them. not want able enter url , view image.
/site /framework /protected /**my php site**/ /www /images /**this storing images**/
- in order restrict viewing of these images need move
images
directory outside ofwww
? if where? - what linux permissions should given on
images
directory? - for images have stored in db want restricted access use access rules within framework. can rules such these limit access images in given directory also?
any info can provided how approach (so can further research) answers questions above helpful.
for images in directory denied (they must access through script , none of them have direct access available - ie server able access them, , have apache mod_rewrite
) can put .htaccess
in directory following:
deny
so answer questions number.. ^^
- no,
.htaccess
take care of same effect. - you'll need read (
+r
) images server. - the framework may have that, can't prevent direct linking if image url known. doing
.htaccess
or moving directory best bet.
Comments
Post a Comment