Hello, I use such a tactic: is there a main page, for example admin.php and through a variable in the gett request ?show=add_product file admin/add_product.php . How to make it so that without the participation of the admin.php page, the admin / add_product.php page is not available. That is, at this address is available: admin.php?show=add_product and for this is not: admin/add_product.php . How to do it? thank

    2 answers 2

    Alternatively, in the admin htaccess folder, register:

     <FilesMatch "\.php$"> Deny from all </FilesMatch> <Files admin.php> Allow from all </Files> 

      In my youth I did this:

      In admin.php created a variable

       $ItAdmin = true; 

      In the rest of the check

       if(isset($ItAdmin) && $ItAdmin!=false) { /// Ваш код }