CVS update: php3/doc/chapters
| From: | paul | Date: | Sun, 16 May 1999 19:46:27 +0000 |
| Subject: | CVS update: php3/doc/chapters | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-5720@lists.php.net to get a copy of this message | ||
Date: Sunday May 16, 1999 @ 15:46
Author: paul
Update of /repository/php3/doc/chapters
In directory php:/tmp/cvs-serv3217/chapters
Modified Files:
features.sgml
Log Message:
Added example
Index: php3/doc/chapters/features.sgml
diff -u php3/doc/chapters/features.sgml:1.26 php3/doc/chapters/features.sgml:1.27
--- php3/doc/chapters/features.sgml:1.26 Sat May 15 17:12:35 1999
+++ php3/doc/chapters/features.sgml Sun May 16 15:46:26 1999
@@ -7,15 +7,17 @@
<simpara>
The HTTP Authentication hooks in PHP are only available when it is
- running as an Apache module. In an Apache module PHP script, it
- is possible to use the <function>Header</function> function to
- send an "Authentication Required" message to the client browser
- causing it to pop up a Username/Password input window. Once the
- user has filled in a username and a password, the URL containing
- the PHP script will be called again with the variables,
+ running as an Apache module and is hence not available in the CGI version.
+ In an Apache module PHP script, it is possible to use the
+ <function>Header</function> function to send an "Authentication Required"
+ message to the client browser causing it to pop up a Username/Password
+ input window. Once the user has filled in a username and a password,
+ the URL containing the PHP script will be called again with the variables,
$PHP_AUTH_USER, $PHP_AUTH_PW and $PHP_AUTH_TYPE set to the user
name, password and authentication type respectively. Only "Basic"
- authentication is supported at this point.
+ authentication is supported at this point. See the <funciton>Header</function
+ function for more information.
+
<para>
An example script fragment which would force client authentication
on a page would be the following:
@@ -65,6 +67,34 @@
server response of 401. This can effectively "log out" a user,
forcing them to re-enter their username and password. Some people
use this to "time out" logins, or provide a "log-out" button.
+ <simpara>
+ <example>
+ <title>HTTP Authentication example forcing a new name/password</title>
+ <programlisting role=php>
+<?php
+ function authenticate() {
+ Header( "WWW-authenticate: basic realm='Test Authentication
System'");
+ Header( "HTTP/1.0 401 Unauthorized");
+ echo "You must enter a valid login ID and password to access this
resource\n";
+ exit;
+ }
+
+ if(!isset($PHP_AUTH_USER) || ($SeenBefore == 1 && !strcmp($OldAuth,
$PHP_AUTH_USER)) ) {
+ authenticate();
+ }
+ else {
+ echo "Welcome: $PHP_AUTH_USER<BR>";
+ echo "Old: $OldAuth";
+ echo "<FORM ACTION=\"$PHP_SELF\" METHOD=POST>\n";
+ echo "<INPUT TYPE=HIDDEN NAME=\"SeenBefore\"
VALUE=\"1\">\n";
+ echo "<INPUT TYPE=HIDDEN NAME=\"OldAuth\"
VALUE=\"$PHP_AUTH_USER\">\n";
+ echo "<INPUT TYPE=Submit VALUE=\"Re
Authenticate\">\n";
+ echo "</FORM>\n";
+
+}
+?>
+ </programlisting>
+ </example>
<simpara>
This behavior is not required by the HTTP Basic authentication
standard, so you should never depend on this. Testing with Lynx
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net