Solved

php script to protect a folder with .htaccess and .htpasswd

Posted on 2010-11-24
5
557 Views
Last Modified: 2012-05-10
Hi
I am looking for a simple php script that will generate (create .htaccess and .htpassword) to protect a folder

as simple as that !
ex: **protect.php?username=admin&password=admin**
and it will create automatially the .htaccess and .htpasswd that protects the folder with user admin/amin

Regards
0
Comment
Question by:yarekGmail
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 8

Expert Comment

by:ropenner
ID: 34210862
<?PHP
//$username = "admin";
//$password = "admin";
$username = $_Request("username");
$password = $_Request("password");

$path = pathinfo(__FILE__,PATHINFO_DIRNAME) . "/";

$default_htaccess_text = <<< endofhtaccesstext
AuthUserFile    $path.htpasswd
AuthGroupFile   /dev/null
AuthName        "Please Enter your Password for this Folder"
AuthType        Basic
<Limit GET POST>
require valid-user
</Limit>
endofhtaccesstext;

$username = preg_replace("/\W/","",$username); // remove any special characters only allowing letters and numbers and underscore .... customize this so system command doesn't become a security hole
$password = preg_replace("/\W/","",$password);

$create = (file_exists("$path.htaccess")?"":"-c");
system("htpasswd $create -b .htpasswd $username $password");
if (!file_exists("$path.htaccess")) {
      if (writeFile("$path.htaccess", $default_htaccess_text)) {
            print "successful write of .htaccess";
      } else {
            print "problem writing .htaccess file";
      }
}

function writeFile($file, $message) {
      if ($handle = fopen($file, "w")) {
            fwrite($handle, imap_qprint($message));
            fclose($handle);
            return true;
      } else {
            return false;
      }
}
?>
0
 
LVL 6

Accepted Solution

by:
V4nP3rs13 earned 500 total points
ID: 34211230
No.. that code that ropenner posted is wrong. I think It has some mistakes.... here's the right code:
<?PHP
//$username = "admin";
//$password = "admin";
$username = $_REQUEST["username"];
$password = $_REQUEST["password"];

$path = pathinfo(__FILE__,PATHINFO_DIRNAME) . "/";

$default_htaccess_text = <<< endofhtaccesstext
AuthUserFile    $path.htpasswd
AuthGroupFile   /dev/null
AuthName        "Please Enter your Password for this Folder"
AuthType        Basic
<Limit GET POST>
require valid-user
</Limit>
endofhtaccesstext;

$username = preg_replace("/\W/","",$username); // remove any special characters only allowing letters and numbers and underscore .... customize this so system command doesn't become a security hole
$password = preg_replace("/\W/","",$password);

$create = (file_exists("$path.htaccess")?"":"-c");
system("htpasswd $create -b .htpasswd $username $password");
if (!file_exists("$path.htaccess")) {
      if (writeFile("$path.htaccess", $default_htaccess_text)) {
            print "successful write of .htaccess";
      } else {
            print "problem writing .htaccess file";
      }
}

function writeFile($file, $message) {
      if ($handle = fopen($file, "w")) {
            fwrite($handle, imap_qprint($message));
            fclose($handle);
            return true;
      } else {
            return false;
      }
}
?>

Open in new window

0
 

Author Comment

by:yarekGmail
ID: 34211471
I executed the script and got : INTERNAL ERROR
It seems the .htpasswd was not written

It seems I cannot execute that on my shared hosting plan:
system("htpasswd $create -b .htpasswd $username $password");

Any idea on how to simply do that ?

regards
0
 
LVL 8

Expert Comment

by:ropenner
ID: 34211673
I assumed UNIX or LINUX, what type of box are you hosted on (windows, unix)?

try just the part of creating the .htaccess file

if (writeFile("$path.htaccess", $default_htaccess_text)) {
   print "successful write of .htaccess";
} else {
   print "problem writing .htaccess file";
}

if you can do that ... then at least you have permission to create files and there may be a way to create the .htpasswd file without using a 'system' call.

On your shared hosting ... what method is provided to manually create the .htpasswd files?
0
 

Author Comment

by:yarekGmail
ID: 34212511
Linux shared server.
There is no problem to create files with writeFile.
the .htaccess was created

But .htpasswd is not created :
it means system("htpasswd $create -b .htpasswd $username $password"); is NOT executed correctly

Regards
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
3 proven steps to speed up Magento powered sites. The article focus is on optimizing time to first byte (TTFB), full page caching and configuring server for optimal performance.
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question