Well, I'll answer myself before anyone else gets the chance to :) --- On Mon, 7/28/08, Bobby Jack <bobbykjack@xxxxxxxxxxx> wrote: > I'm thinking [the problem] can be resolved using > RewriteRule with an appropriate condition on HTTP_REFERER. It seems as if I cannot determine the HTTP_REFERER when it's a secure->non-secure request, even within the same domain. Back to the drawing-board, I guess - does anyone have any cunning ideas? - Bobby --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx