如何禁止直接访问视频文件与streamer.php,仅允许嵌入播放?
Solution to Block Direct Access to Video Files and Streamer
Step 1: Fix the .htaccess in the videos Folder
Your current .htaccess only blocks requests from external domains, but allows direct access (where the HTTP_REFERER header is empty). Replace it with rules that block any request not originating from watch.php:
RewriteEngine On # Block access to PHP/MP4 files unless referer includes watch.php RewriteCond %{HTTP_REFERER} ^$ [OR] RewriteCond %{HTTP_REFERER} !watch\.php [NC] RewriteRule \.(php|mp4)$ - [F,L,NC]
How This Works:
RewriteCond %{HTTP_REFERER} ^$: Catches direct requests where no referer header is sent.RewriteCond %{HTTP_REFERER} !watch\.php [NC]: Catches requests where the referer doesn't includewatch.php(case-insensitive).RewriteRule \.(php|mp4)$ - [F,L,NC]: Returns a 403 Forbidden response for any PHP or MP4 file that meets either condition.
If your local setup uses a subfolder (e.g., http://localhost/my-project/watch.php), make the referer check more specific to avoid false blocks:
RewriteCond %{HTTP_REFERER} !^http://localhost/my-project/watch\.php$ [NC]
Step 2: Add Extra Validation in streamer.php
As a fallback (since HTTP_REFERER can be spoofed or omitted in rare cases), add a check directly in the streamer script to ensure the request comes from watch.php:
<?php // Validate referer before streaming $referer = $_SERVER['HTTP_REFERER'] ?? ''; if (strpos($referer, 'watch.php') === false) { header('HTTP/1.1 403 Forbidden'); exit('Access denied'); } $stream = new VideoStream("example video.mp4"); $stream->start(); ?>
Additional Notes:
- This setup won't stop highly determined users (e.g., those spoofing referer headers via dev tools), but it raises the barrier for casual downloaders.
- Ensure your
VideoStreamclass supports partial requests (range headers) to enable smooth browser playback of longer videos.
内容的提问来源于stack exchange,提问作者connorjrt
相关产品推荐
相关产品推荐

