Below is a javascript snippet that I use as part of an AJAX script. How to prevent user direct access to user_back_end_friends.php? I don’t want people to be able to go to domain.com/user_back_end_friends.php and see a list of friends.
Javascript Code:
<script type="text/javascript">
$(document).ready(function() {
$("#user_friends").tokenInput("/user_back_end_friends.php", {
theme: "sometheme", userid: "<?php echo $id; ?>"
});
});
</script>
This is what I found, but not sure how to implement it using javascript code above:
I use this on the page I need to call:
$included=1;include("user_back_end_friends.php");
When I have to prevent direct access, I use:
if(!$included){ die("Error"); }
But how to add this $ included part of the script to my javascript code?
ariel source
share