Re: Evaluating PHP scripts for use on one-login site
| From: | Rasmus Lerdorf | Date: | Sun, 17 Dec 2000 19:14:18 +0000 |
| Subject: | Re: Evaluating PHP scripts for use on one-login site | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-5298@lists.php.net to get a copy of this message | ||
That's a pretty vague question and thus rather hard to answer. The main
thing you need to decide from the start is how you want to do your
authentication. You really have 3 main choices:
1. Do it outside of PHP using one of Apache mod_auth modules and .htaccess
or httpd.conf configuration.
2. Use PHP's HTTP auth mechanism described here:
http://www.php.net/manual/features.http-auth.php
3. Use PHP to create a non-HTTP based authentication mechanism. It could
use cookies or the session code and wouldn't have one of those
pop-up auth windows that HTTP auth forces you to use.
Once you decide on an auth mechanism then you need to decide on where to
store your user/password data. It sounds like you have a MySQL database
so it would be a good idea to store it there. For (1.) there is a
mod_auth_mysql module available for Apache. However, (2.) might be
preferable since your scripts are likely to use MySQL for other things and
you would be able to authenticate and access the database for other
purposes over a single connection per request. If you use mod_auth_mysql
each request would need 2 connections to complete.
As far as looking at 3rd party packages to integrate into your system. I
would suggest looking for the package that gives you the most
functionality. Don't worry too much about integrating the auth system.
Once you have written yours it is not hard to hack up most of these things
you can download and pull out their auth system and insert your own.
After all they are written in PHP, it is easy stuff...
-Rasmus
On Sun, 17 Dec 2000, Lynn Siprelle wrote:
> Hi guys--
>
> New user of PHP and MySQL, already making headway in a very short time and am astonished at how
> totally cool it all it. As always when I learn new stuff I'm jumping in to the deep end--or at
> least it seems like the deep end to me. :)
>
> Basically what I want to do is offer a range of services to my website users and have them only
> have to log into the site *once*. I'm seeing tutorials etc on authentication/tracking, well and
> good, will do.
>
> What I would like is some advice on how to evaluate existing scripts (like chat, bulletin
> boards, etc) for integrating into that type of system. What, if anything, should I look for?
> I'm not at all averse to figuring out how to tie things together myself, but it would be nice
> to hear what to do and what NOT to do from experienced folks who've done it--things to watch
> out for, if there are such things.
>
> Regards,
> Lynn
> --
> Siprelle & Associates: Distinctive Web Design Since 1994
> Lynn Siprelle, President: Newest Associate Josie born 9/9/97
> Business: lynn@siprelle com | Personal: lynsa@siprelle.com
> Portfolio: http://www.siprelle.com/ | TNH:
> http://www.newhomemaker.com/
>
> --
> PHP Database Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> For additional commands, e-mail: php-db-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>