views:

281

answers:

2

I have a members only area on my site where users can login and view Windows Media streaming content.

I have created a PHP script to serve the ASX file however I cannot validate this with session information. I think this is because the WMP is making the request and not a php page.

Can anyone suggest an elegant way to protect ASX files?

A: 

You can try this:

//$user->isAuthenticated is only for ilustration, use whatever method you
//use to check if the user is authenticated
if($user->isAuthenticated()) {
      $asx = file_get_contents("/path/to/my/file.asx");
      header("Content-type: video/x-ms-asf");
      echo $asx;
} else {
      //Tell the user that he can't view this asx
}
Nathan
A: 

What I would do is incorporate the PHP session ID into the .asx request. Normally this identifier is stored in a cookie, and passed to PHP on each page request. In this case WMP is not sending a cookie along, so you have no way of knowing whether or not the request is authenticated or not.

When you output the download link for the ASX file, tack on the session identifier as a GET variable:

$download_link = "http://myserver.com/download_asx_file.php?"
$download_link .= "f=$file_id&";
$download_link .= htmlspecialchars(SID);

Now when you call session_start() at the top of download_asx_file.php it should find and load your session correctly, and allow you to authenticate as normal.

Note: The SID constant is evaluated to PHPSESSID=12345678 (or whatever that user's session happens to be)

sixthgear