*Serious* problems with HTTP_AUTH (and PHP?)
| From: | Boget, Chris | Date: | Mon, 12 Jun 2000 18:23:05 +0000 |
| Subject: | *Serious* problems with HTTP_AUTH (and PHP?) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-1641@lists.php.net to get a copy of this message | ||
Here is my situation:
We use authentication very similar to what is demonstrated
in the manual. We send a 401 header to pop up the login
dialog then we take that information and query a mysql
database to determine if the login is valid.
To get into the site, the user is taken to a file: login.php3.
The only thing in that file is a call to my master login
function that validates the ID/PW information, determines
what type of user it is and directs them to the proper place
(via a header() call). If the information is incorrect, the
function returns and the page then displays an error.
In each page of the password protected section of the site,
I call a different function that just validates the ID/PW and
boots the user out if it is not correct. The problem I'm
experiencing is more with the login.php3 and here it is:
A user will go to that page and put in their ID/PW to log
in. The information is good and so they are allowed in.
They go about their business, finish up and close out the
browser. Now, someone different goes to the site and they
are taken to the login.php3 page. They do not have a
valid ID/PW and so after 3 tries, they are given the afore-
mentioned error message and click the back button to
go back to the previous menu. However, if that user then
clicks the forward button to return and see the error
message, the user is instead presented with the menu for
the user who previosuly logged in. It is as if the browser
caches the previous users authentication information. While
I do not know if this is the case, I do know that it is caching
something because this only happens when the browser is
not set up to check for new versions of a web page every visit.
If the browser is set up to check every time, this problem does
not occur.
Since this is almost certainly a caching issue, I thought I'd
be able to nip the problem in the bud by sending the
following headers right before I send the 401 authentication
header:
header("Pragma: no-cache");
header("Cache-Control: no-cache, must-revalidate");
header("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT");
header("Expires: Mon, 26 Jul 1997 05:00:00 GMT");
However, that did not solve my problem and I'm not sure why.
Has anyone ever experienced something like this? Does any
one have any suggestions?
Here is the sample code. Copy into their respective pages and
when the authentication dialog pops up, type in "bob" as the
user name. You will be taken to page two. Exit the browser.
Go back to page1.php3, but this time, type something else as
the user name. You will be given the message that you failed.
Click the back button then click the forward button. You will
now see the message that you are at page2, even though you
did not pass the auth.
page1.php3
<script language="php">
if(!isset($PHP_AUTH_USER)) {
Header("WWW-Authenticate: Basic realm=\"My Realm\"");
Header("HTTP/1.0 401 Unauthorized");
if( $PHP_AUTH_USER == "bob" ) {
header( "location: ./page2.php3" );
exit();
}
echo "You Failed!!\n";
exit;
} else {
header( "location: ./page2.php3" );
exit();
}
</script>
page2.php3
<script language="php">
echo "You made it to page 2!!<br>\n";
</script>
Any help would be most gratefully appreciated!!
Chris