# PHP/MySQL + protect directory

**URL:** <https://forum.kirupa.com/t/php-mysql-protect-directory/251894>\
**Category:** programming\
**Created:** [February 13, 2008, 5:52pm UTC](https://forum.kirupa.com/t/php-mysql-protect-directory/251894 "2008-02-13T17:52:30Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Macro\_design](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@Macro\_design](https://forum.kirupa.com/u/Macro_design)\
**Post date:** [February 13, 2008, 5:52pm UTC](https://forum.kirupa.com/t/php-mysql-protect-directory/251894/1 "2008-02-13T17:52:30Z")

</div>

Hi there

I’m currently working on a closed site. The idea is to allow people to sign-up and log-in to the site, storing the members in a MySQL database. That part is working just fine.

However, as I’m using $\_SESSION to allow or deny users access to the site, directories aren’t protected, so if I upload say a .pdf file anyone with the url could download it.

The question is: Should I use .htaccess to protect my directories? And if yes, how do I use my $\_SESSION in the .htaccess code (if that is even possible)?

Thanks a lot
