Re: auth_user and auth_pw through URL
| From: | Johan Hanson | Date: | Tue, 22 Aug 2000 21:54:15 +0000 |
| Subject: | Re: auth_user and auth_pw through URL | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-13183@lists.php.net to get a copy of this message | ||
Adam Cantrell wrote:
>
> Is there a way I can pass the auth_user and auth_pw variables as URL
> variables that are masked? What i would like, is something that looks like
> this www.url.com?username=****&pass=**** where the **** strings are masked.
> I don't want the browser's basic authentication window to pop up because the
> user has already logged in through our web based form over SSL. I just want
> a way for the files to be accessable, but I don't want users to be able to
> just copy the URL and send it to their friends - or just guess file names.
You could "sign" the links.
With each link, pass as parameters:
- a counter, that is incremented by 1 each time a page is loaded
- a user identifier
- a key, computed as md5($counter . $user_id . $password)
or using some other cryptographic hash function.
The server would need to know the password for the user.
The password is never transmitted unencrypted.
All the web server has to do to authenticate a user is then to recompute the
key and test if it matches with the supplied key.
This approach is still vulnerable to users copying the URL and using it again
in another session. The solution to that problem would be to restrict the
validity of the password used to, say, from one document to the next here and
now and/or only during a finite amount of time.
Note that the parameters do not have to be passed as ?-parameters.
You could use cookies, but remember that smart users are able to copy cookies
just as well as URLs. The good thing with cookies is that a single cookie
can be used cookie for browsing in multiple windows.
/*
All this talk of cookies made me hungry...
<crunch> Gingerbread is yummy. =)
*/
If you use Apache, you could use URL rewriting to pass parameters as directory
names in the request which mod_rewrite would rewrite to parameters to a script.
The URL would be something like:
http://www.yoursite.com/download/<user_id>/<counter>/<key>/<filename>
The configuration directives would be something like:
RewriteEngine on
RewriteRule ^/download/.*/.*/.*/.* /download.php?uid=$1&cnt=$2&key=$3$file=$4
And the script download.php would be:
<?php
<look up the password for user $uid and store in $passwd>
$new_key = md5($cnt . $uid . $passwd);
if ($key == $newkey) {
header ("Content-type: image/gif"); // or whatever
readfile ("secure/directory/$file");
exit();
} else {
header ("http/1.0 404 Not Found");
include "404.html";
exit();
}
?>
The point is that the filename will not be mangled when saved by the
user's browser. Just make sure that your php script does not contain anything
else
than php code before exit().
Also, do not use auto_prepend_file for the directory where the script is
located.
Hope this helps.
/ Johan
-- johan@tiq.com -- http://www.obsession.se/johan/ --