π Hidden URL - Secure File Access System
Hash-based URL system for secure file access - Protect PDFs, images, videos and other files from direct access.
- π Secure Access: Protect your files with hash-based URLs
- π Referer Control: Allow access only from specific domains
- π Multi-Format Support: PDF, images, videos and other file types
- β‘ Fast & Lightweight: Maximum performance with minimal PHP code
- π‘οΈ Security: Prevent direct file access
- π§ Easy Integration: Easily integrate into existing projects
- PHP 7.4 or higher
- Web server (Apache, Nginx, etc.)
- File read permissions
- Clone the project:
git clone https://github.com/byrmstf/hidden-url.git
cd hidden-url-
Copy files to your web server's root directory
-
Place your files in the
documents/folder -
Update hash values in
img.phpfile:
$file_config = array(
'your-file-hash' => array(
'file' => 'your-file.pdf',
'type' => 'application/pdf',
'size' => 123456
),
);// Define file hashes in img.php file
$file_config = array(
'05edd57091ad570303df856c652a7a174554a148' => array(
'file' => 'sample.pdf',
'type' => 'application/pdf',
'size' => 433994
),
);<object data="/img.php?h=05edd57091ad570303df856c652a7a174554a148"
type="application/pdf" width="100%" height="800px">
<embed width="100%" height="1000px"
src="/img.php?h=05edd57091ad570303df856c652a7a174554a148"/>
</object>// Referer control (optional)
$allowed_domains = ['yourdomain.com', 'www.yourdomain.com'];
$referer = $_SERVER['HTTP_REFERER'] ?? '';
$is_allowed = false;
foreach ($allowed_domains as $domain) {
if (strpos($referer, $domain) !== false) {
$is_allowed = true;
break;
}
}
if (!$is_allowed) {
http_response_code(403);
die('Access denied');
}// Generate secure hash for file
$filename = 'document.pdf';
$hash = hash('sha1', $filename . time() . 'your-secret-salt');// Different file types
$file_config = array(
'pdf-hash' => array(
'file' => 'document.pdf',
'type' => 'application/pdf',
'size' => 123456
),
'img-hash' => array(
'file' => 'image.jpg',
'type' => 'image/jpeg',
'size' => 78901
),
'vid-hash' => array(
'file' => 'video.mp4',
'type' => 'video/mp4',
'size' => 2345678
),
);- Referer Control: Access only from specific domains
- Hash-Based Access: Hide file names
- Direct Access Prevention: Restrict folder access
- SSL Support: Optimized for HTTPS connections
- File Validation: Size and existence checks
- Security Headers: XSS and clickjacking protection
hidden-url/
βββ index.php # Main page
βββ img.php # File service script
βββ documents/ # Files storage folder
β βββ sample.pdf # Sample PDF file
βββ .github/
β βββ workflows/
β βββ ci.yml # CI/CD pipeline
βββ README.md # This file
βββ CONTRIBUTING.md # Contribution guide
βββ LICENSE # MIT License
βββ composer.json # Dependencies
βββ .gitignore # Git ignore file
- Download and extract the files
- Upload to your web server
- Add your files to the
documents/folder - Update the hash configuration in
img.php - Test the system by accessing
index.php
- GitHub Pages Demo: https://byrmstf.github.io/hidden-url/
- Interactive Demo: https://byrmstf.github.io/hidden-url/demo.html
# Clone the project
git clone https://github.com/byrmstf/hidden-url.git
cd hidden-url
# Start PHP server
php -S localhost:8000
# Open in browser
# http://localhost:8000- π Secure File Access - See how hash-based URLs work
- π PDF Viewer - Test with sample PDF file
- π Referer Control - Understand domain restrictions
- β‘ Performance - Experience fast file delivery
- Fork the project
- Create your feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
For more details, see CONTRIBUTING.md
This project is licensed under the MIT License - see the LICENSE file for details.
Mustafa Bayram
- Website: mustafabayram.com.tr
- GitHub: @byrmstf
If you like this project, please give it a star! β
If you find a bug or have a suggestion, please report it on the Issues page.
- GitHub Pages Demo - Static documentation and overview
- Interactive Demo - Interactive demo with setup instructions
# Quick start
git clone https://github.com/byrmstf/hidden-url.git
cd hidden-url && php -S localhost:8000
# Visit: http://localhost:8000- π Documentation: README.md
- π Live Demo: GitHub Pages
- π» Interactive Demo: Try Now
- π₯ Download: Latest Release
β If you like this project, don't forget to give it a star!