PHP 4.0 Bug #8220 Updated: When i give unset($PHP_AUTH_USER) it's not destroying the variable
| From: | rasmus@php.net | Date: | Wed, 13 Dec 2000 08:39:41 +0000 |
| Subject: | PHP 4.0 Bug #8220 Updated: When i give unset($PHP_AUTH_USER) it's not destroying the variable | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-41125@lists.php.net to get a copy of this message | ||
ID: 8220
Updated by: rasmus
Reported By: kpsdevi@pol.net.in
Old-Status: Open
Status: Closed
Bug Type: *Function Specific
Assigned To:
Comments:
It is destroying it, but your browser is sending it again on the next request so PHP sets it again.
There is no way to tell the browser not to send this variable short of sending another 401 with a
different realm. This is a browser issue and has nothing to do with PHP.
Previous Comments:
---------------------------------------------------------------------------
[2000-12-13 03:27:43] kpsdevi@pol.net.in
i included the following code in one file.
<?php
if(!isset($PHP_AUTH_USER))
{
header('WWW-Authenticate: Basic Realm="Enter your login name and
password"');
header('HTTP/1.0 401 Unauthorized');
echo 'Authorization required'; exit;
}
else { require("mysqlconn.inc");
$sql = "select password from users where username = '$PHP_AUTH_USER'";
$result = mysql_query($sql,$conn); $row = mysql_fetch_array($result);
if($PHP_AUTH_PW != $row[0])
{ header('WWW-Authenticate: Basic Realm="Authorization failed : Enter Username and
password"');
header('HTTP/1.0 401 Unauthorized');
echo 'Authorization required';
mysql_free_result($result);
mysql_close();
exit;
}
mysql_free_result($result);
mysql_close();
}
?>
I have included the following code to logout the user
<?
unset($PHP_AUTH_USER);
?>
but it's not destroying the variable $PHP_AUTH_USER.
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8220