Re: htpasswd
| From: | php3 at developersdesk dot com | Date: | Tue, 15 Aug 2000 05:35:41 +0000 |
| Subject: | Re: htpasswd | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-11733@lists.php.net to get a copy of this message | ||
Addressed to: "Andrew" <fisherres@msn.com>
"PHP General" <php-general@lists.php.net>
** Reply to note from "Andrew" <fisherres@msn.com> Sun, 13 Aug 2000 21:29:30 -0700
>
> Thanks for the reply, but how can I add a user to the .htpasswd file
> via PHP?
After you do everything I already mentioned so you can write to the file
from an Apache process, you do this:
# If you are creating a new file, and adding all the entries use 'w'
# instead of 'a' as the open mode.
$F = fopen( 'filename', 'a' );
# If you have more than on eentry to add, do this in a loop.
fputs( $F, $Username . ':' . crypt( $Password ) . "\n" );
fclose( $F );
> Addressed to: "Andrew" <fisherres@msn.com> php-general@lists.php.net
>
> ** Reply to note from "Andrew" <fisherres@msn.com> Sun, 13 Aug 2000
> 20:25:57 -0700
> >
> > Hello,
> >
> > I have a .htpasswd file which has usernames and passwords for the
> > specified people I'd like to grant access to. I'm using http
> > authentication because I'd like to avoid all the hassles w/ sessions
> > (not that I dislike them, just I'd have to redesign my site's
> > architecture). What I want to do is allow PHP to manipulate this file
> > by adding, editing, and deleting users. I know I can do this by using
> > htpasswd, but how can I do this using PHP?
>
>
> o Create a directory somewhere, preferably outside of DocumentRoot so
> the web server can not send its contents.
>
> o Set the ownership of the directory so the user and/or group the web
> server runs as.
>
> o Move your password file to this directory, and change the ownership
> and permissions so the web server can write it.
>
> o Point the web server at this file to check usernames.
>
> Now PHP run by the web server can write the file. Be aware that
> _anyone_ who can write PHP code on the machine can write the file, and
> break into your site. On a shared server this is NOT safe.
>
>
>
> I suggest you store the username and password (and anything else you
> want to keep track of about your users) in a database. It is easier to
> maintain than a password file. You can do it with just a file, but
> then _you_ have to worry about locking and making sure two people
> don't trash the file by trying to change it at the same time.
>
>
> If you use a database, after each transaction that changes the
> username list you do a select of all the usernames and passwords from
> the table, and write a new file.
>
> If you have a large number of users and heavy loads, you might want to
> create a temporary file, in the same directory as the password file,
> and when it is complete close it, delete the password file and rename
> the temp file to be the password file. This reduces the windows when
> people can not login as much as possible.
>
Rick Widmer
Internet Marketing Specialists
www.developersdesk.com