#1
  1. A Change of Season
    Devshed Frequenter (2500 - 2999 posts)

    Join Date
    Mar 2004
    Location
    Next Door
    Posts
    2,650
    Rep Power
    171

    Htaccess allow from not working


    Hello;

    I have a folder I want it to be only accessible from paypal.com and sexualsonics.com

    So I save this .htaccess in the folder:

    Code:
    Order Deny,Allow
    deny from All
    allow from paypal.com
    allow from sexualsonics.com
    But I still get 403 from both sites.

    What am I doing wrong?

    Thanks
  2. #2
  3. No Profile Picture
    Lost in code
    Devshed Supreme Being (6500+ posts)

    Join Date
    Dec 2004
    Posts
    8,317
    Rep Power
    7170
    These sites are somehow requesting pages from your folder? Are you talking about something like an IPN request?

    paypal.com is going to resolve back to different hosts depending on when and where the request originates. The host making the IPN request is not going to resolve to paypal.com.
    PHP FAQ

    Originally Posted by Spad
    Ah USB, the only rectangular connector where you have to make 3 attempts before you get it the right way around
  4. #3
  5. A Change of Season
    Devshed Frequenter (2500 - 2999 posts)

    Join Date
    Mar 2004
    Location
    Next Door
    Posts
    2,650
    Rep Power
    171
    Originally Posted by E-Oreo
    These sites are somehow requesting pages from your folder? Are you talking about something like an IPN request?
    Yes

    Originally Posted by E-Oreo
    paypal.com is going to resolve back to different hosts depending on when and where the request originates. The host making the IPN request is not going to resolve to paypal.com.
    Wow, I didn't understand any of that!
  6. #4
  7. Code Monkey V. 0.9
    Devshed Regular (2000 - 2499 posts)

    Join Date
    Mar 2005
    Location
    A Land Down Under
    Posts
    2,095
    Rep Power
    1990
    Originally Posted by zxcvbnm
    Wow, I didn't understand any of that!
    Well, PayPal doesn't use the domain paypal.com for any of their API calls. I can't remember what they do use off the top of my head, but it's most likely something like api.paypal.com or some combination of sub-domains that they use.

    Also remember that PayPal has different domain extensions, so you can also use the same sort of thing from paypal.com.au for example.
  8. #5
  9. No Profile Picture
    Lost in code
    Devshed Supreme Being (6500+ posts)

    Join Date
    Dec 2004
    Posts
    8,317
    Rep Power
    7170
    In a nut shell this:
    Well, PayPal doesn't use the domain paypal.com for any of their API calls.
    There isn't a single domain or IP that PayPal uses to send IPN requests to you. That's why the IPN API has a built in system for checking the validity of requests.
    PHP FAQ

    Originally Posted by Spad
    Ah USB, the only rectangular connector where you have to make 3 attempts before you get it the right way around

IMN logo majestic logo threadwatch logo seochat tools logo