HTTP authentication
| From: | Arcady Genkin | Date: | Mon, 04 Sep 2000 19:21:38 +0000 |
| Subject: | HTTP authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-15170@lists.php.net to get a copy of this message | ||
I've set up an initial login page as per the PHP manual's section on
http authentication. It compares the password to that stored in a
database and then decides upon whether to let the user in or not.
What is the common approach for the other pages that I want to be
protected by the authentication? Do I need to include the
WWW-Authenticate header from each of them? I tried that and it seems
to result in a new Login dialog poped up upon opening each of them.
I notice that the PHP_AUTH_USER variable is available in the
subsequent documents even without including the WWW-Authenticate
header. Is it safe to simply rely on that and just include a database
check if that user is logged in?
Thanks,
--
Arcady Genkin
Don't read everything you believe.