#51011 [NEW]: The Content and the sample were mixed

From: Date: Thu, 11 Feb 2010 09:18:10 +0000
Subject: #51011 [NEW]: The Content and the sample were mixed
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3866@lists.php.net to get a copy of this message
From: lne1030 at gmail dot com Operating system: Windows XP PHP version: 5.2.12 PHP Bug Type: Translation problem Bug description: The Content and the sample were mixed Description: ------------ http://docs.php.net/manual/zh/features.http-auth.php This page have the error! "Example #7 Digest HTTP" Reproduce code: --------------- <?php $realm = 'Restricted area'; //user => password $users = array('admin' => 'mypass', 'guest' => 'guest'); if (empty($_SERVER['PHP_AUTH_DIGEST'])) { header('HTTP/1.1 401 Unauthorized'); header('WWW-Authenticate: Digest realm="'.$realm. '" qop="auth" nonce="'.uniqid().'" opaque="'.md5($realm).'"'); die('Text to send if user hits Cancel button'); } // analyze the PHP_AUTH_DIGEST variable if (!($data = http_digest_parse($_SERVER['PHP_AUTH_DIGEST'])) || !isset($users[$data['username']])) die('Wrong Credentials!'); // generate the valid response $A1 = md5($data['username'] . ':' . $realm . ':' . $users[$data['username']]); $A2 = md5($_SERVER['REQUEST_METHOD'].':'.$data['uri']); $valid_response = md5($A1.':'.$data['nonce'].':'.$data['nc'].':'.$data['cnonce'].':'.$data['qop'].':'.$A2); if ($data['response'] != $valid_response) die('Wrong Credentials!'); // ok, valid username & password echo 'Your are logged in as: ' . $data['username']; // function to parse the http auth header function http_digest_parse($txt) { // protect against missing data $needed_parts = array('nonce'=>1, 'nc'=>1, 'cnonce'=>1, 'qop'=>1, 'username'=>1, 'uri'=>1, 'response'=>1); $data = array(); preg_match_all('@(\w+)=([\'"]?)([a-zA-Z0-9=./\_-]+)\2@', $txt, $matches, PREG_SET_ORDER); foreach ($matches as $m) { $data[$m[1]] = $m[3]; unset($needed_parts[$m[1]]); } return $needed_parts ? false : $data; } ?> </programlisting> </example> </para> <note> <title>¼æÈÝÐÔÎÊÌâ</title> <para> ÔÚ±àд HTTP ±êÍ·´úÂëʱÇë¸ñÍâСÐÄ¡£ÎªÁ˶ÔËùÓеĿͻ§¶Ë±£Ö¤¼æÈÝÐÔ£¬¹Ø¼ü×Ö¡°Basic¡±µÄµÚÒ»¸ö×Öĸ±ØÐë´óдΪ¡°B¡±£¬·Ö½ç×Ö·û´®±ØÐëÓÃË«ÒýºÅ£¨²»Êǵ¥ÒýºÅ£©ÒýÓ㻲¢ÇÒÔÚ±êÍ·ÐÐ <emphasis>HTTP/1.0 401</emphasis> ÖУ¬ÔÚ <emphasis>401</emphasis> ǰ±ØÐëÓÐÇÒ½öÓÐÒ»¸ö¿Õ¸ñ¡£ </para> </note> <para> ÔÚÒÔÉÏÀý×ÓÖУ¬½ö½öÖ»´òÓ¡³öÁË <varname>PHP_AUTH_USER</varname> ºÍ <varname>PHP_AUTH_PW</varname> µÄÖµ£¬µ«ÔÚʵ¼ÊÔËÓÃÖУ¬¿ÉÄÜÐèÒª¶ÔÓû§ÃûºÍÃÜÂëµÄºÏ·¨ÐÔ½øÐмì²é¡£»òÐí½øÐÐÊý¾Ý¿âµÄ²éѯ£¬»òÐí´Ó dbm ÎļþÖмìË÷¡£ </para> <para> ×¢ÒâÓÐЩ Internet Explorer ä¯ÀÀÆ÷±¾ÉíÓÐÎÊÌâ¡£Ëü¶Ô±êÍ·µÄ˳ÐòÏÔµÃËÆºõÓе㴵ëÇó´Ã¡£Ä¿Ç°¿´À´ÔÚ·¢ËÍ <literal>HTTP/1.0 401</literal> ֮ǰÏÈ·¢ËÍ <emphasis>WWW-Authenticate</emphasis> ±êÍ·ËÆºõ¿ÉÒÔ½â¾ö´ËÎÊÌâ¡£ </para> <simpara> ×Ô PHP 4.3.0 Æð£¬ÎªÁË·ÀÖ¹ÓÐÈËͨ¹ý±àд½Å±¾À´´ÓÓô«Í³Íⲿ»úÖÆÈÏÖ¤µÄÒ³ÃæÉÏ»ñÈ¡ÃÜÂ룬µ±ÍⲿÈÏÖ¤¶ÔÌØ¶¨Ò³ÃæÓÐЧ£¬²¢ÇÒ&safemode;±»¿ªÆôʱ£¬PHP_AUTH ±äÁ¿½«²»»á±»ÉèÖᣵ«ÎÞÂÛÈçºÎ£¬<varname>REMOTE_USER</varname> ¿ÉÒÔ±»ÓÃÀ´±æÈÏÍⲿÈÏÖ¤µÄÓû§£¬Òò´Ë¿ÉÒÔÓà <varname>$_SERVER['REMOTE_USER']</varname> ±äÁ¿¡£ </simpara> <note> <title>ÅäÖÃ˵Ã÷</title> <para> PHP ÓÃÊÇ·ñÓÐ <literal>AuthType</literal> Ö¸ÁîÀ´ÅжÏÍⲿÈÏÖ¤»úÖÆÊÇ·ñÓÐЧ¡£ </para> </note> <simpara> ×¢Ò⣬ÕâÈÔÈ»²»ÄÜ·ÀÖ¹ÓÐÈËͨ¹ýδÈÏÖ¤µÄ URL À´´Óͬһ·þÎñÆ÷ÉÏÈÏÖ¤µÄ URL ÉÏ͵ȡÃÜÂë¡£ </simpara> <simpara> Netscape Navigator ºÍ Internet Explorer ä¯ÀÀÆ÷¶¼»áÔÚÊÕµ½ 401 µÄ·þÎñ¶Ë·µ»ØÐÅϢʱÇå¿ÕËùÓеı¾µØä¯ÀÀÆ÷Õû¸öÓòµÄ Windows ÈÏÖ¤»º´æ¡£ÕâÄܹ»ÓÐЧµÄ×¢ÏúÒ»¸öÓû§£¬²¢ÆÈʹËûÃÇÖØÐÂÊäÈëËûÃǵÄÓû§ÃûºÍÃÜÂë¡£ÓÐЩÈËÓÃÕâÖÖ·½·¨À´Ê¹µÇ¼״̬¡°¹ýÆÚ¡±£¬»òÕß×÷Ϊ¡°×¢Ïú¡±°´Å¥µÄÏìÓ¦ÐÐΪ¡£ </simpara> <para> <example> <title>Ç¿ÆÈÖØÐÂÊäÈëÓû§ÃûºÍÃÜÂëµÄ HTTP ÈÏÖ¤µÄ·¶Àý</title> <programlisting role="php"> <![CDATA[ <?php function authenticate() { header('WWW-Authenticate: Basic realm="Test Authentication System"'); header('HTTP/1.0 401 Unauthorized'); echo "You must enter a valid login ID and password to access this resource\n"; exit; } if (!isset($_SERVER['PHP_AUTH_USER']) || ($_POST['SeenBefore'] == 1 && $_POST['OldAuth'] == $_SERVER['PHP_AUTH_USER'])) { authenticate(); } else { echo "<p>Welcome: {$_SERVER['PHP_AUTH_USER']}<br />"; echo "Old: {$_REQUEST['OldAuth']}"; echo "<form action='{$_SERVER['PHP_SELF']}' METHOD='post'>\n"; echo "<input type='hidden' name='SeenBefore' value='1' />\n"; echo "<input type='hidden' name='OldAuth' value='{$_SERVER['PHP_AUTH_USER']}' />\n"; echo "<input type='submit' value='Re Authenticate' />\n"; echo "</form></p>\n"; } -- Edit bug report at http://bugs.php.net/?id=51011&edit=1 -- Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=51011&r=trysnapshot52 Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=51011&r=trysnapshot53 Try a snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=51011&r=trysnapshot60 Fixed in SVN: http://bugs.php.net/fix.php?id=51011&r=fixed Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=51011&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=51011&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=51011&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=51011&r=needscript Try newer version: http://bugs.php.net/fix.php?id=51011&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=51011&r=support Expected behavior: http://bugs.php.net/fix.php?id=51011&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=51011&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=51011&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=51011&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=51011&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=51011&r=dst IIS Stability: http://bugs.php.net/fix.php?id=51011&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=51011&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=51011&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=51011&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=51011&r=mysqlcfg

« previous php.doc.bugs (#3866) next »