Bug #14534: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism

From: Date: Sat, 15 Dec 2001 10:37:05 +0000
Subject: Bug #14534: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism
Groups: php.dev 
Request: Send a blank email to php-dev+get-73892@lists.php.net to get a copy of this message
From: sitnikov@infonet.ee Operating system: Linux PHP version: 4.1.0 PHP Bug Type: Apache related Bug description: Variables $PHP_AUTH_* is set, when use a traditional external auth mechanism .htaccess AuthUserFile .htpasswd AuthName "WARNING! ENTER ACCESS KEY!" AuthType Basic Require valid-user index.php <pre> $PHP_AUTH_USER <? var_dump($PHP_AUTH_USER); ?> $PHP_AUTH_PW <? var_dump($PHP_AUTH_PW); ?> <pre> http://www.php.net/manual/en/features.http-auth.php <cut> In order to prevent someone from writing a script which reveals the password for a page that was authenticated through a traditional external mechanism, the PHP_AUTH variables will not be set if external authentication is enabled for that particular page. In this case, the $REMOTE_USER variable can be used to identify the externally-authenticated user. </cut> -- Edit bug report at: http://bugs.php.net/?id=14534&edit=1

« previous php.dev (#73892) next »