Thanks
But the .htaccess referer rules are easily bypassed eg. the refspoof extension in Firefox or the referer flag in wget. Plus it seems that authorised Mac users have alot of issues with this method.
I am hoping for something that only allows access to the path/page/file if the user has logged in, a session id is the obvious answer but it doesn’t look like WordPress supports this. I have found the nonces (number used once) api but there are no plugins written for it.
Surely there is a more professional option for content security? Paying for it is not an issue either if it comes to that.