Below is a javascript snippet that I am using as part of a AJAX script. How do I prevent user_back_end_friends.php from being accessed directly? I don't want people to be able to go to domain.com/user_back_end_friends.php and see a list of friends.
Javascript Code:
<script type="text/javascript">
$(document).ready(function() {
$("#user_friends").tokenInput("/user_back_end_friends.php", {
theme: "sometheme", userid: "<?php echo $id; ?>"
});
});
</script>
This is what I found but not sure how to implement it with the javascript code above:
I use this in the page I need to call it in:
$included=1;include("user_back_end_friends.php");
When I have to prevent direct access I use:
if(!$included){ die("Error"); }
But how do I add this $included part of the script in my javascript code?