New Zenner
- Join Date:
- Dec 2006
- Posts:
- 19
- Plugin Contributions:
- 0
Specialized Catalog links for approved customers only?
We have a wholesale business, and all our customers must be preapproved before they're allowed to view our prices and purchase products. But once a customer has been approved, we provide them with a link to download our current inventory data - including prices - so they can import it into their own systems quickly and easily, whenever they need it.
The URL's for those links aren't published on the site anywhere for the public to see, but we're concerned that if those URLs somehow get out to noncustomers, we'll lose control over who can see our prices and who can't.
So here's the question: Is there a way we can password-protect those files? Here's what the page code looks like currently:
<code> <?phpheader("Content-type: application/csv");
header("Content-Disposition: attachment; filename=filename_download.txt");
header("Pragma: no-cache");
header("Expires: 0");
if (file_exists('includes/configure.php')) {
/**
* load the main configure file.
*/
include('includes/configure.php');
} else {
header('location: zc_install/index.php');
}
$dbc = @mysql_connect(DB_SERVER,DB_SERVER_USERNAME,DB_SERVER_PASSWORD) OR die ('Could not connect to database: ' . mysql_error());
@mysql_select_db(DB_DATABASE) or die ('Could not select the database: ' . mysql_error());
$query="SELECT manufacturers_name AS manufacturer, products_model AS sku, products_quantity AS quantity, products_price AS price, products_msrp AS msrp, products_name AS name, products_salesperweek as salesperweek FROM products AS p, manufacturers AS m, products_description AS pd WHERE p.manufacturers_id = m.manufacturers_id AND pd.products_id = p.products_id ORDER BY manufacturer, sku";
$result=mysql_query($query);
$cr = "\n";
$tab = "\t";
if($result) {
$data = 'Manufacturer' . $tab . 'SKU' . $tab . 'Quantity' . $tab . 'Price' . $tab . 'MSRP' . $tab . 'Name' . $cr;
while ($row = mysql_fetch_array ($result, MYSQL_ASSOC))
{
$data .= $row['manufacturer'] . $tab . $row['sku'] . $tab . $row['quantity'] . $tab . number_format($row['price'],2) . $tab . number_format($row['msrp'],2) . $tab . $row['name'] . $cr;
}
mysql_free_result($result);
echo $data;
}
else {
echo '<p>The inventory list is currently unavailable. Sorry for the inconvenience. Please contact us to report this problem.</p>';
}
</code>
Thank you in advance!