Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7825649
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 2, 20262026-06-02T09:05:54+00:00 2026-06-02T09:05:54+00:00

Today I got an issue, which says I should hide some files from the

  • 0

Today I got an issue, which says I should hide some files from the public. Actually these are some “user specific” files so others than the owner should not be able to see them.

I didn’t want to read the files with fread or something like that if there are other options so I did some research about the problem and found X-Sendfile mod for apache on an other thread here on SO.

It works almost as I need it. Except one thing.
The files are hidden with htaccess, they aren’t visible for the “world” and I can serve them with X-Sendfile header after authentication.

BUT what if someone create a php script what does the same thing as mine? Users may remember the urls for the files. The files will be available for them. That’s bad…

Do you have any idea what can I do to prevent others than the owners to access their files without permissions? I need a solution for nginx at first.

The files are on a server without PHP, it’s only a static file server.

Moving files to an other directory won’t work, it would make much more pain.

Thank you

UPDATE
It seems like I missed that the downloaded file was 0Kb or something like that, because I wasn’t able to do the trick again.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-02T09:05:56+00:00Added an answer on June 2, 2026 at 9:05 am

    BUT what if someone create a php script what does the same thing as mine?

    Why are you letting users upload arbitrary code?

    Users may remember the urls for the files.

    Users will never see the URLs except for the script that uses X-Sendfile.

    Do you have any idea what can I do to prevent others than the owners to access their files without permissions?

    Verify their auth in the script that uses X-Sendfile.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Today I got some new restrictions on my WPF user interface that should eliminate
Today I got this question for which I think I answered very bad. I
Today I've got a stacktrace with a very strange error. Actually, I may be
I've got an asp.net application which seems to forget that a user is logged
I've done this hundreds of times before without issue, but today I've got a
This question got me today, my repositories should always return full objects? They can
I have followed some advices I got here today and would need a bit
Today I got our svn repository cloned into git. I had some uncommitted work
today I got confused when doing a couple of <%=Html.LabelFor(m=>m.MyProperty)%> in ASP.NET MVC 2
Today I got my new PC ( Windows 7 , 32 bit) and installed

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.