Re: htpasswd

From: Date: Mon, 14 Aug 2000 05:16:37 +0000
Subject: Re: htpasswd
Groups: php.general 
Request: Send a blank email to php-general+get-11556@lists.php.net to get a copy of this message
Addressed to: "Andrew" <fisherres@msn.com> php-general@lists.php.net ** Reply to note from "Andrew" <fisherres@msn.com> Sun, 13 Aug 2000 20:25:57 -0700 > > Hello, > > I have a .htpasswd file which has usernames and passwords for the > specified people I'd like to grant access to. I'm using http > authentication because I'd like to avoid all the hassles w/ sessions > (not that I dislike them, just I'd have to redesign my site's > architecture). What I want to do is allow PHP to manipulate this file > by adding, editing, and deleting users. I know I can do this by using > htpasswd, but how can I do this using PHP? o Create a directory somewhere, preferably outside of DocumentRoot so the web server can not send its contents. o Set the ownership of the directory so the user and/or group the web server runs as. o Move your password file to this directory, and change the ownership and permissions so the web server can write it. o Point the web server at this file to check usernames. Now PHP run by the web server can write the file. Be aware that _anyone_ who can write PHP code on the machine can write the file, and break into your site. On a shared server this is NOT safe. I suggest you store the username and password (and anything else you want to keep track of about your users) in a database. It is easier to maintain than a password file. You can do it with just a file, but then _you_ have to worry about locking and making sure two people don't trash the file by trying to change it at the same time. If you use a database, after each transaction that changes the username list you do a select of all the usernames and passwords from the table, and write a new file. If you have a large number of users and heavy loads, you might want to create a temporary file, in the same directory as the password file, and when it is complete close it, delete the password file and rename the temp file to be the password file. This reduces the windows when people can not login as much as possible. Rick Widmer Internet Marketing Specialists www.developersdesk.com

« previous php.general (#11556) next »