Re: htpasswd
| From: | php3 at developersdesk dot com | Date: | Mon, 14 Aug 2000 05:16:37 +0000 |
| Subject: | Re: htpasswd | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-11556@lists.php.net to get a copy of this message | ||
Addressed to: "Andrew" <fisherres@msn.com>
php-general@lists.php.net
** Reply to note from "Andrew" <fisherres@msn.com> Sun, 13 Aug 2000 20:25:57 -0700
>
> Hello,
>
> I have a .htpasswd file which has usernames and passwords for the
> specified people I'd like to grant access to. I'm using http
> authentication because I'd like to avoid all the hassles w/ sessions
> (not that I dislike them, just I'd have to redesign my site's
> architecture). What I want to do is allow PHP to manipulate this file
> by adding, editing, and deleting users. I know I can do this by using
> htpasswd, but how can I do this using PHP?
o Create a directory somewhere, preferably outside of DocumentRoot so
the web server can not send its contents.
o Set the ownership of the directory so the user and/or group the web
server runs as.
o Move your password file to this directory, and change the ownership
and permissions so the web server can write it.
o Point the web server at this file to check usernames.
Now PHP run by the web server can write the file. Be aware that
_anyone_ who can write PHP code on the machine can write the file, and
break into your site. On a shared server this is NOT safe.
I suggest you store the username and password (and anything else you
want to keep track of about your users) in a database. It is easier to
maintain than a password file. You can do it with just a file, but then
_you_ have to worry about locking and making sure two people don't trash
the file by trying to change it at the same time.
If you use a database, after each transaction that changes the username
list you do a select of all the usernames and passwords from the table,
and write a new file.
If you have a large number of users and heavy loads, you might want to
create a temporary file, in the same directory as the password file, and
when it is complete close it, delete the password file and rename the
temp file to be the password file. This reduces the windows when people
can not login as much as possible.
Rick Widmer
Internet Marketing Specialists
www.developersdesk.com