Re: auth_user and auth_pw through URL

From: Date: Tue, 22 Aug 2000 21:54:15 +0000
Subject: Re: auth_user and auth_pw through URL
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-13183@lists.php.net to get a copy of this message
Adam Cantrell wrote: > > Is there a way I can pass the auth_user and auth_pw variables as URL > variables that are masked? What i would like, is something that looks like > this www.url.com?username=****&pass=**** where the **** strings are masked. > I don't want the browser's basic authentication window to pop up because the > user has already logged in through our web based form over SSL. I just want > a way for the files to be accessable, but I don't want users to be able to > just copy the URL and send it to their friends - or just guess file names. You could "sign" the links. With each link, pass as parameters: - a counter, that is incremented by 1 each time a page is loaded - a user identifier - a key, computed as md5($counter . $user_id . $password) or using some other cryptographic hash function. The server would need to know the password for the user. The password is never transmitted unencrypted. All the web server has to do to authenticate a user is then to recompute the key and test if it matches with the supplied key. This approach is still vulnerable to users copying the URL and using it again in another session. The solution to that problem would be to restrict the validity of the password used to, say, from one document to the next here and now and/or only during a finite amount of time. Note that the parameters do not have to be passed as ?-parameters. You could use cookies, but remember that smart users are able to copy cookies just as well as URLs. The good thing with cookies is that a single cookie can be used cookie for browsing in multiple windows. /* All this talk of cookies made me hungry... <crunch> Gingerbread is yummy. =) */ If you use Apache, you could use URL rewriting to pass parameters as directory names in the request which mod_rewrite would rewrite to parameters to a script. The URL would be something like: http://www.yoursite.com/download/<user_id>/<counter>/<key>/<filename> The configuration directives would be something like: RewriteEngine on RewriteRule ^/download/.*/.*/.*/.* /download.php?uid=$1&cnt=$2&key=$3$file=$4 And the script download.php would be: <?php <look up the password for user $uid and store in $passwd> $new_key = md5($cnt . $uid . $passwd); if ($key == $newkey) { header ("Content-type: image/gif"); // or whatever readfile ("secure/directory/$file"); exit(); } else { header ("http/1.0 404 Not Found"); include "404.html"; exit(); } ?> The point is that the filename will not be mangled when saved by the user's browser. Just make sure that your php script does not contain anything else than php code before exit(). Also, do not use auto_prepend_file for the directory where the script is located. Hope this helps. / Johan -- johan@tiq.com -- http://www.obsession.se/johan/ --

« previous php.general (#13183) next »