httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jim Strickland <j...@americanroamer.com>
Subject [users@httpd] Password protected folder within another password protected folder
Date Mon, 15 Mar 2004 20:21:37 GMT
I have a client section on my website. The way it is set up, a client 
goes to the clients only page of my website and click on the link number 
that has been assigned to them. They are then presented with a window to 
type in their login and password. Once that is done, they are given 
access to their own client section from which they can download files 
only. I have one client that would like to go one step further though. 
This client has one employee that needs a folder within their client 
section that only he can access, but he still needs access to all of the 
other folders and files that all employees of that client have access 
to. I have been using the Webmin GUI to Apache to try and set this up, 
but with no luck. I have a regular password file set up for this 
client's entire client section. The one employee is listed in the 
password file as well as the general login for this client. Thus 
everybody has access to all the files. I then set up a per directory 
directive for the one folder that only the one employee should have 
access to. I also set up a new password file for this directory, with 
only the one employee in it. However, the problem is getting it so only 
this one employee has access to the folder. If I set permissions on the 
folder so that the owner is Apache with rwx privileges, group rwx 
privileges are set for the one user's personal group, and no privileges 
are set for others, then anyone logging in with the standard client 
login is still able to see and access the private folder. However, if I 
set ownership of the folder to root (as it wants to default to) or to 
the one user, noone, including the intended user, is able to even see 
the folder. I'm guessing that there is an important step I am missing. 
Could someone please identify what that step is?

-- 
James Strickland - MCP
IT Manager
American Roamer
901-377-8585
http://www.americanroamer.com


---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
   "   from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org


Mime
View raw message