Re: PHP_AUTH + .htaccess

From: Date: Wed, 09 Aug 2000 20:56:49 +0000
Subject: Re: PHP_AUTH + .htaccess
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-10993@lists.php.net to get a copy of this message
Here's what I use for one of the sites i do .htaccess on its an include file... hope it helps: <? // Brendan W. McAdams <brendan@plexmedia.com> // Plexus M/2, Inc. <http://www.plexmedia.com> // $Id: authenticate.php,v 1.4 2000/06/20 17:43:58 brendan Exp $ // ............................................................................ ............ // .authenticate.php $Revision: 1.4 - branched to Ocean Club $ . // .User Authentication System using .htaccess style Access Control . // ............................................................................ ............ // Created for Plexus InterACTIVE ION Intranet App. function check_auth() { global $PHP_AUTH_USER; global $PHP_AUTH_PW; if (!$PHP_AUTH_USER) { require_login(); } else { $sth = MYSQL_QUERY("SELECT * FROM users WHERE email='$PHP_AUTH_USER' AND password = '$PHP_AUTH_PW' and type='owner'"); $rows = MYSQL_NUM_ROWS($sth); if ($rows == 0) { require_login(); } $cursor = MYSQL_FETCH_ARRAY($sth); $user_id = $cursor['ID']; $first_name = $cursor['first_name']; $last_name = $cursor['last_name']; MYSQL_FREE_RESULT($sth); return array ($user_id, $first_name, $last_name); } } function require_login() { // pop up ye olde authorisation dialog box header('WWW-Authenticate: Basic realm="Lazy Day Club (Your Username is your e-Mail Address)"'); header('HTTP/1.0 401 Unauthorized'); echo 'Authorization Required.'; exit; } ?> ----- Brendan W. McAdams | ph. (305)377-2880 email: brendan@plexmedia.com | cell: (305)218-6466 Programmer/Systems Administrator | pager: (305)277-4879 Plexus M/2, Inc. | fax: (305)377-2870 http://www.plexmedia.com "Always listen to the experts; they'll tell you what can't be done and why. Then do it." - Robert A. Heinlein ----- Original Message ----- From: "Mike Waychison" <mwaychison@cobalt.com> To: <php-general@lists.php.net> Sent: Wednesday, August 09, 2000 12:40 PM Subject: [PHP] PHP_AUTH + .htaccess I have it set up so that I have a .htaccess file in a directory along with a php page that has phpinfo() in it. By trying to access the php page, I get the standard 401 created by the .htaccess file, but then I can read the PHP_AUTH_USER and PHP_AUTH_PW, even though the manual says this *should not* work. Is this something I can rely upon? Or will I have to run a hacked version of PHP whenever this gets fixed? Mike Waychison mikew@php.net -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#10993) next »