Hi all, We have a site and we have created an admin section where the admin can upload documents. We have made a user login section where they can view a list of the documents (from the DB) and download the file. We want to make the site however not allow ppl to type in the path of the document and retrieve the file. How is this accomplished? Are the documents stored in a hidden / non-web accessible directory? Or is this restricted with APACHE? Please advise Thanks in advance. Web: http://www.elemental.co.za -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php