CVS update: php3/doc/chapters

From: Date: Sun, 16 May 1999 19:46:27 +0000
Subject: CVS update: php3/doc/chapters
Groups: php.dev 
Request: Send a blank email to php-dev+get-5720@lists.php.net to get a copy of this message
Date: Sunday May 16, 1999 @ 15:46 Author: paul Update of /repository/php3/doc/chapters In directory php:/tmp/cvs-serv3217/chapters Modified Files: features.sgml Log Message: Added example Index: php3/doc/chapters/features.sgml diff -u php3/doc/chapters/features.sgml:1.26 php3/doc/chapters/features.sgml:1.27 --- php3/doc/chapters/features.sgml:1.26 Sat May 15 17:12:35 1999 +++ php3/doc/chapters/features.sgml Sun May 16 15:46:26 1999 @@ -7,15 +7,17 @@ <simpara> The HTTP Authentication hooks in PHP are only available when it is - running as an Apache module. In an Apache module PHP script, it - is possible to use the <function>Header</function> function to - send an "Authentication Required" message to the client browser - causing it to pop up a Username/Password input window. Once the - user has filled in a username and a password, the URL containing - the PHP script will be called again with the variables, + running as an Apache module and is hence not available in the CGI version. + In an Apache module PHP script, it is possible to use the + <function>Header</function> function to send an "Authentication Required" + message to the client browser causing it to pop up a Username/Password + input window. Once the user has filled in a username and a password, + the URL containing the PHP script will be called again with the variables, $PHP_AUTH_USER, $PHP_AUTH_PW and $PHP_AUTH_TYPE set to the user name, password and authentication type respectively. Only "Basic" - authentication is supported at this point. + authentication is supported at this point. See the <funciton>Header</function + function for more information. + <para> An example script fragment which would force client authentication on a page would be the following: @@ -65,6 +67,34 @@ server response of 401. This can effectively "log out" a user, forcing them to re-enter their username and password. Some people use this to "time out" logins, or provide a "log-out" button. + <simpara> + <example> + <title>HTTP Authentication example forcing a new name/password</title> + <programlisting role=php> +&lt;?php + function authenticate() { + Header( &quot;WWW-authenticate: basic realm='Test Authentication System'&quot;); + Header( &quot;HTTP/1.0 401 Unauthorized&quot;); + echo &quot;You must enter a valid login ID and password to access this resource\n&quot;; + exit; + } + + if(!isset($PHP_AUTH_USER) || ($SeenBefore == 1 && !strcmp($OldAuth, $PHP_AUTH_USER)) ) { + authenticate(); + } + else { + echo &quot;Welcome: $PHP_AUTH_USER<BR>&quot;; + echo &quot;Old: $OldAuth&quot;; + echo &quot;<FORM ACTION=\&quot;$PHP_SELF\&quot; METHOD=POST>\n&quot;; + echo &quot;<INPUT TYPE=HIDDEN NAME=\&quot;SeenBefore\&quot; VALUE=\&quot;1\&quot;>\n&quot;; + echo &quot;<INPUT TYPE=HIDDEN NAME=\&quot;OldAuth\&quot; VALUE=\&quot;$PHP_AUTH_USER\&quot;>\n&quot;; + echo &quot;<INPUT TYPE=Submit VALUE=\&quot;Re Authenticate\&quot;>\n&quot;; + echo &quot;</FORM>\n&quot;; + +} +?> + </programlisting> + </example> <simpara> This behavior is not required by the HTTP Basic authentication standard, so you should never depend on this. Testing with Lynx -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#5720) next »