Bug #14534 Updated: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism

From: Date: Thu, 13 Jun 2002 22:14:48 +0000
Subject: Bug #14534 Updated: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10408@lists.php.net to get a copy of this message
ID: 14534 Updated by: sniper@php.net Reported By: sitnikov@infonet.ee -Status: Open +Status: Closed Bug Type: Apache related Operating System: Linux PHP Version: 4.1.0 New Comment: This bug has been fixed in CVS. You can grab a snapshot of the CVS version at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2001-12-15 05:37:04] sitnikov@infonet.ee .htaccess AuthUserFile .htpasswd AuthName "WARNING! ENTER ACCESS KEY!" AuthType Basic Require valid-user index.php <pre> $PHP_AUTH_USER <? var_dump($PHP_AUTH_USER); ?> $PHP_AUTH_PW <? var_dump($PHP_AUTH_PW); ?> <pre> http://www.php.net/manual/en/features.http-auth.php <cut> In order to prevent someone from writing a script which reveals the password for a page that was authenticated through a traditional external mechanism, the PHP_AUTH variables will not be set if external authentication is enabled for that particular page. In this case, the $REMOTE_USER variable can be used to identify the externally-authenticated user. </cut> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=14534&edit=1

« previous php.bugs (#10408) next »