Greta wrote: > > My server (webhotel) is powered by Apache. I have logged into waff > and password protected the files that I want to be protecred. Is > this secure enough or do I still have to put .htaccess files there > (in data and lib.)? If you have password protected the files, you have probably created .htaccess files, somewhat different to the ones described in the FAQ, though. You should be able to see them through your FTP program. I suppose that password protection via .htaccess files is secure enough, but I recommend that you test that the script works as intended with the password protection set, so it doesn't stop and ask for passwords when the files are used by the script. / Gunnar