Invalid Login1"; elseif ($username = "Jonathan") if ($password != "forte") echo "

Invalid Login2

"; elseif ($password = "forte") echo " Protected Page

Welcome ".$username."


Think of a nice username and password that later on have to be typed in from everyone who wants to see your protected pages. Take the pen and the piece of paper and write these down. And don't forget: Wherever you use capital letters those who want to access your pages will have to use capital letters as well!!!

Use your ftp-Program to access your Web-Server. There you create a directory where you want to place the password protected files using the 'make new dir' command from the Commands menu (you can name it whatever you want). Then you create a second directory where you will later place the file with the password information (again use the 'make new dir' command). Now take the pen and the paper and write down the complete and exact path of the directory you created for the password information file(the ftp-program should display this if you open the directory).

Open your text editor and write the following lines:

AuthUserFile xxx/.htpasswd
AuthGroupFile /dev/null
AuthName yyy
AuthType Basic

<Limit GET>
require user zzz
</Limit>

After you have done this you replace the xxx with the path you have written down on your piece of paper. Furthermore you replace the yyy with one ore more nice words. These words are only there to make the procedure of accessing your protected pages a little bit nicer. Because if someone wants to access these pages he will first see a nice box that asks him for the username and password. The first sentence in the box will be: Enter username for yyy. Then you replace the zzz with the username you have written down on your piece of paper. Finally you save this file somewhere on you computer under the name htaccess.txt

Open your browser and go to the page http://www.euronet.nl/~arnow/htpasswd/ There you fill in the form with the data from your piece of paper and push the calculate button. A new page will appear on which you will find a line in large letters that starts off with the username you have written on your piece of paper and some strange letters afterwards. Take again your pen and write the whole (!!!) line down.

Open your editor again and type the line you have just written down on your piece of paper. Push Return to create an empty line below. Now save this file under the name htpasswd.txt.

Now open your ftp-program again and access your WWW-Server. First go to the directory where you want to place your protected pages and copy the file htaccess.txt from your computer to this directory. The name of the file should appear on the Remote side of the ftp-program. Mark this file and execute the 'Rename'command from the Commands menu to rename the file to .htaccess (don't forget the dot!!!) Now execute the 'change file attributes'-command from the Commands menu. A box appears where you type in 644 where it says 'manual'. Now you change to the directory where you want to place the password information. To there you copy the file htpasswd.txt. You then rename it to .htpasswd (again don't forget the dot!!!). Then you do what you already did to the htaccess file, i.e. you mark the file, execute the 'change file attributes'-command from the Commands menu and type in 644 where it says 'manual'. Now we are nearly done. The last thing you have to do is to close the directory where you are in, mark it and once again execute the 'change file attributes'-command from the Commands menu. But now you type in 711 where it says manual.

Burns, Joe. 'So You Want A Password Protected Page, Huh?.' htmlgoodies. 01 May 2005. 3 Apr 2007 .

First, copy the code in the above box and paste it into an HTML web page. The page could be named whatever you'd like: index.html for example.

Look for a line in the script that reads... if (form.id.value=='userID') { This is the username. Change 'userID' it to whatever username you'd like to use.

Now look for a line in the script that reads... if (form.pass.value=='password') { Change 'password' to the one you'd like to use.

Now look for a line that says... location='page2.html' This is the URL of the page that the person will be directed to when they enter the correct password. Keep in mind this assume that the page is located in the same directory of the page the password script is on. You may have to edit the path accordingly. If you're not sure, just put the complete URL of the page here. Example: http://www.yourdomain.com/file.html

The next step is optional. This is only if you want to alter the error messages that are displayed when the username or password is not entered correctly. If you don't change anything in these lines, the default error messages will display. Look for a line that says... alert('Invalid Password')

You can change 'Invalid Password' to whatever message you'd like. For example, you can make it say, 'The password you entered is incorrect. Please try again.'

You can also do the same to the user Invalid ID section. Look for the line... } else { alert('Invalid UserID')

Change 'Invalid UserID' to whatever message you'd like to display when the username is incorrect.

"Password Protect a Web Page." 2 Create A Website. 4th Apr 2007. 4 Apr 2007 <http://www.2createawebsite.com/enhance/password-protect.html>.

Since Apache is used on more than 50% of the sites on the WWW, we'll start there. Apache allows you to protect a document, an entire directory, or files that match a certain pattern, and allow them to be accessed by a certain user, a group of users, or users from a certain domain or machine.

These settings can be made either in the main server configuration files, or in a .htaccess (pronounced "dot H T Access") file in the direcory to be affected. I will assume that the settings will be made in a .htaccess file, since that is the usual way of doing this.

There are several steps in the process, and you need to do those ones that apply to your situation, and the effect that you are trying to achieve.

First you will need to create a .htpasswd file, containing the names and passwords of the users that will need to have access to the site. On Unix systems, the password is encrypted, and must be created using the htpasswd program. Typing "htpasswd" at the command line will produce the output:

Usage: htpasswd [-c] passwordfile username  The -c flag creates a new file  

If you get a "Command not found" error message, contact your sysadmin.

ALWAYS put the password file outside of the document root of your server. I typically put the file in a directory called "passwd" that is on the same directory level as the htdocs directory. This is so that malicious persons cannot download my password files for perusal at their own leisure.

It is conventional to call the file ".htpasswd" Thus, to create a new password file with your username and password in it, type:

htpasswd -c .htpasswd myusername

You will them be queried for a password, and then asked to confirm that password. If you look at the file that was created, it will contain a line that looks something like:

myusername:WPKOMv50Rqnk2

You can add additional names to the file by repeating the command without the -c switch.

On Apache for Win32, the passwords are encrypted using the MD5 algorithm, rather than the Unix crypt algorithm, so the password file will look a little different.

If you wish to add several of the users to a group, create another file called .htgroup, with entries in it like:

group: user1 anotheruser myusername

You next step is to actually protect the directory or file(s) in question.

In the directory to be protected, create a file called .htaccess, and put something in it like:

AuthUserFile /home/www/passwd/.htpasswd  AuthGroupFile /home/www/passwd/.htgroup  AuthName Protected  AuthType Basic  require group groupname  

In this example, the directory requires the user to be a member of the group "groupname". The AuthName is the word that will appear on the authentication dialog. AuthType must be Basic, since no other authentication schemes are supported at this time.

To allow just one username, rather than a whole group, use the following:

AuthUserFile /home/www/passwd/.htpasswd  AuthGroupFile /dev/null  AuthName JustMe  AuthType Basic  require user me  
"Password protecting web pages." The HTML Writers Guild. 23 Oct 2003. 4 Apr 2007 <http://www.hwg.org/lists/hwg-servers/passwords.html>.

.htaccess files (or "distributed configuration files") provide a way to make configuration changes on a per-directory basis. A file, containing one or more configuration directives, is placed in a particular document directory, and the directives apply to that directory, and all subdirectories thereof.

Note: If you want to call your .htaccess file something else, you can change the name of the file using the AccessFileName directive. For example, if you would rather call the file .config then you can put the following in your server configuration file:

AccessFileName .config

What you can put in these files is determined by the AllowOverride directive. This directive specifies, in categories, what directives will be honored if they are found in a .htaccess file. If a directive is permitted in a .htaccess file, the documentation for that directive will contain an Override section, specifying what value must be in AllowOverride in order for that directive to be permitted.

For example, if you look at the documentation for the AddDefaultCharset directive, you will find that it is permitted in .htaccess files. (See the Context line in the directive summary.) The Override line reads "FileInfo". Thus, you must have at least "AllowOverride FileInfo" in order for this directive to be honored in .htaccess files.

Example:

Context: server config, virtual host, directory, .htaccess
Override: FileInfo

If you are unsure whether a particular directive is permitted in a .htaccess file, look at the documentation for that directive, and check the Context line for ".htaccess."

'; ".htaccess files." Apache. 4th Apr 2007. 4 Apr 2007 <http://httpd.apache.org/docs/1.3/howto/htaccess.html> ?>