Just spitballing here, (I'm not trying to answer my own question, but adding to it as I think)
Could session_cookie_path be combined with something in the htaccess like RewriteCond %{HTTP_COOKIE}? Like having the htaccess verify a cookie exists in a certain directory?
Yeah, I realize cookies can be faked, though they'd have to login to know which cookie it is they need to fake. And they still need to login access the page that loads the swf. A deny rule wouldn't work in my case (which was really my whole problem) because of the way the flash file was calling images.
The modwrite actually worked just fine, I created a snippet which creates a cookie on the login redirect page. Then I used this htaccess file
RewriteEngine on
RewriteCond %{HTTP_COOKIE} !cookiename
RewriteRule ^(.*)$ http://yourwebsite/403/$1 [r=301,nc]
So [for the htaccess challenged that may stumble on this] what's happening here is that if the cookie isn't found, it's rewriting the request to the sites 403 page.
Again, is this the most locked down way ever in history? No, but it's not too bad.
BTW, this was just my solution, if anyone else has a better suggestion, please feel free!