Bug #14534: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism
| From: | sitnikov at infonet dot ee | Date: | Sat, 15 Dec 2001 10:37:05 +0000 |
| Subject: | Bug #14534: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-73892@lists.php.net to get a copy of this message | ||
From: sitnikov@infonet.ee
Operating system: Linux
PHP version: 4.1.0
PHP Bug Type: Apache related
Bug description: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism
.htaccess
AuthUserFile .htpasswd
AuthName "WARNING! ENTER ACCESS KEY!"
AuthType Basic
Require valid-user
index.php
<pre>
$PHP_AUTH_USER
<?
var_dump($PHP_AUTH_USER);
?>
$PHP_AUTH_PW
<?
var_dump($PHP_AUTH_PW);
?>
<pre>
http://www.php.net/manual/en/features.http-auth.php
<cut>
In order to prevent someone from writing a script which reveals the
password for a page that was authenticated through a traditional external
mechanism, the PHP_AUTH variables will not be set if external
authentication is enabled for that particular page. In this case, the
$REMOTE_USER variable can be used to identify the externally-authenticated
user.
</cut>
--
Edit bug report at: http://bugs.php.net/?id=14534&edit=1