AUTHENTICATION PROBLEMS
| From: | Toby Miller | Date: | Mon, 11 Sep 2000 19:35:43 +0000 |
| Subject: | AUTHENTICATION PROBLEMS | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-16221@lists.php.net to get a copy of this message | ||
I'm trying to get a functional authentication process and it's not working out too well
for me. I am using the following code:
<?php
if(!isset($PHP_AUTH_USER)) {
Header("WWW-authenticate: basic realm=\"$GTITLE\"");
Header("HTTP/1.0 401 Unauthorized");
echo "You must enter a valid login ID and password to access this
resource\n";
exit;
}
else {
# Assume this user was valid and preset some variables
$userID = 10000;
$userValid = true;
}
?>
This works on Linux running Apache with one exception. If I have a ..htaccess file in any parent
directories to the one executing this include then it fails miserably. It just continually asks for
a username and password and never authenticates. If I remove the .htaccess file from the parent
directory it works fine. Now if I put this on NT running IIS I get nothing. It just prints out the
failure message and never even asks for a username or password. I also tried this script which
someone claimed worked on IIS:
<?php
if ($PHP_AUTH_USER == "" && $PHP_AUTH_PW == "" &&
ereg("^Basic ", $HTTP_AUTHORIZATION)) {
list($PHP_AUTH_USER, $PHP_AUTH_PW) = explode(":",
base64_decode(substr($HTTP_AUTHORIZATION, 6)));
}
$authenticated = 0;
if ($PHP_AUTH_USER != "" || $PHP_AUTH_PW != "") {
file://put your authentication here (e.g. database lookup)
$authenticated = ($PHP_AUTH_USER == "test" && $PHP_AUTH_PW = "123");
}
if(!$authenticated) {
header("WWW-Authenticate: Basic realm=\"$GTITLE\"");
if (ereg("Microsoft", $SERVER_SOFTWARE)) {
header("Status: 401 Unauthorized");
echo "You must enter a valid login ID and password to access this
resource<br>";
exit;
}
else {
header("HTTP/1.0 401 Unauthorized");
echo "You must enter a valid login ID and password to access this
resource<br>";
exit;
}
}
?>
This also fails the same way that the one above does (on IIS). The variables $PHP_AUTH_USER and
$PHP_AUTH_PW and $PHP_AUTH_TYPE are all blank. It just prints out the failure message. Also, since
$SERVER_SOFTWARE is also blank it doesn't even print the proper 401 header.
Any comments, suggestions, fixes are appreciated.
Thanks,
Toby