HTTP authentication

From: Date: Mon, 04 Sep 2000 19:21:38 +0000
Subject: HTTP authentication
Groups: php.general 
Request: Send a blank email to php-general+get-15170@lists.php.net to get a copy of this message
I've set up an initial login page as per the PHP manual's section on http authentication. It compares the password to that stored in a database and then decides upon whether to let the user in or not. What is the common approach for the other pages that I want to be protected by the authentication? Do I need to include the WWW-Authenticate header from each of them? I tried that and it seems to result in a new Login dialog poped up upon opening each of them. I notice that the PHP_AUTH_USER variable is available in the subsequent documents even without including the WWW-Authenticate header. Is it safe to simply rely on that and just include a database check if that user is logged in? Thanks, -- Arcady Genkin Don't read everything you believe.

« previous php.general (#15170) next »