RE: [PHP] PHP 4 Sessions
| From: | Boget, Chris | Date: | Thu, 31 Aug 2000 20:52:11 +0000 |
| Subject: | RE: [PHP] PHP 4 Sessions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-14685@lists.php.net to get a copy of this message | ||
> > Maybe I said the wrong thing, but the intent would be one single
> > login for the 3 secured domains. Since I cannot use basic auth
> > (since that works on both host and realm) to allow the user to log
> > in once at the portal and pass that info along to the other domains,
> > I figured I could have the user log in at the portal, set up a session
> > (with session ID) and have the other 3 sites check for the session
> > ID and use it for authentication accordingly.
> > Am I misunderstanding something?
> Nope, that would work. I just don't see why you cannot make
> that auth page simply available on all virtual hosts. I.e.
> you could simply include() the code, use symlinks or map some
> common code into all domains by using Apache's Alias command.
The code included on all the secured sites is the same (the same function
accessing the same databases, etc). However, the problem is with basic
authentication in that it only authenticates for 1 particular host/realm.
So I cannot authenticate for www.portal.com (realm: portal) and link
the user to a secured page on www.his-site.com w/o the auth dialog
box popping up.
So I would need to create a routine where the user can go to either of
the above sites and have the authentication work the same. In the case
of sessions, I would just check the existance of the session ID, check to
see if it exists and if it does, let them on through. If it doesn't, send
the
401 header and authenticate them. The only other solution we found
was using Apache's Alias command and setting it up so that
www.portal.com/his-site/
was the same as
www.his-site.com/
and that is basically making it so that we are losing the 'brand' of
"his-site.com" (so to speak).
If we are doing something wrong or there is an easier way to do this, I'm
more than open to suggestions...
Chris