Re: PHP_AUTH + .htaccess
| From: | Brendan W. McAdams | Date: | Wed, 09 Aug 2000 20:56:49 +0000 |
| Subject: | Re: PHP_AUTH + .htaccess | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-10993@lists.php.net to get a copy of this message | ||
Here's what I use for one of the sites i do .htaccess on
its an include file...
hope it helps:
<?
// Brendan W. McAdams <brendan@plexmedia.com>
// Plexus M/2, Inc. <http://www.plexmedia.com>
// $Id: authenticate.php,v 1.4 2000/06/20 17:43:58 brendan Exp $
//
............................................................................
............
// .authenticate.php $Revision: 1.4 - branched to Ocean Club $
.
// .User Authentication System using .htaccess style Access Control .
//
............................................................................
............
// Created for Plexus InterACTIVE ION Intranet App.
function check_auth() {
global $PHP_AUTH_USER;
global $PHP_AUTH_PW;
if (!$PHP_AUTH_USER) {
require_login();
} else {
$sth = MYSQL_QUERY("SELECT * FROM users WHERE email='$PHP_AUTH_USER' AND
password = '$PHP_AUTH_PW' and type='owner'");
$rows = MYSQL_NUM_ROWS($sth);
if ($rows == 0) {
require_login();
}
$cursor = MYSQL_FETCH_ARRAY($sth);
$user_id = $cursor['ID'];
$first_name = $cursor['first_name'];
$last_name = $cursor['last_name'];
MYSQL_FREE_RESULT($sth);
return array ($user_id, $first_name, $last_name);
}
}
function require_login() {
// pop up ye olde authorisation dialog box
header('WWW-Authenticate: Basic realm="Lazy Day Club (Your Username is
your e-Mail Address)"');
header('HTTP/1.0 401 Unauthorized');
echo 'Authorization Required.';
exit;
}
?>
-----
Brendan W. McAdams | ph. (305)377-2880
email: brendan@plexmedia.com | cell: (305)218-6466
Programmer/Systems Administrator | pager: (305)277-4879
Plexus M/2, Inc. | fax: (305)377-2870
http://www.plexmedia.com
"Always listen to the experts; they'll tell you what can't be done and why.
Then do it."
- Robert A. Heinlein
----- Original Message -----
From: "Mike Waychison" <mwaychison@cobalt.com>
To: <php-general@lists.php.net>
Sent: Wednesday, August 09, 2000 12:40 PM
Subject: [PHP] PHP_AUTH + .htaccess
I have it set up so that I have a .htaccess file in a directory along
with a php page that has phpinfo() in it. By trying to access the php
page, I get the standard 401 created by the .htaccess file, but then I
can read the PHP_AUTH_USER and PHP_AUTH_PW, even though the manual says
this *should not* work.
Is this something I can rely upon? Or will I have to run a hacked
version of PHP whenever this gets fixed?
Mike Waychison
mikew@php.net
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net