Re: *Serious* problems with HTTP_AUTH (and PHP?)

From: Date: Mon, 12 Jun 2000 18:40:42 +0000
Subject: Re: *Serious* problems with HTTP_AUTH (and PHP?)
Groups: php.general 
Request: Send a blank email to php-general+get-1643@lists.php.net to get a copy of this message
Are you using the same machine to log in with after quitting? You shouldn't experience this on two separate machines with two separate logins. Most (all?) browsers cache the username and password. Most of them also remove them when the user quits the browser. Some (IE for the Mac, for example, maybe IE for the PC), keep the auth information between quits. Usually not for more than a day, as far as I can tell. I don't believe that this caching is the same as the regular web page caching, so I don't think the pragma headers will help. What has been suggested on the list before is to set up your authentication scheme using some kind of timestamp in the realm. You may want to search the archives for more info about that. Paul ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Paul Burney Webmaster and Internet Developer Educational Technology Unit Graduate School of Education and Information Studies University of California, Los Angeles (310) 825-8365 <webmaster@gseis.ucla.edu> <http://www.gseis.ucla.edu/> ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ---------- >From: "Boget, Chris" <chris@wild.net> >To: "'php-general@lists.php.net'" <php-general@lists.php.net>, >"Php3 (E-mail)" <php3@lists.php.net> >Subject: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (and PHP?) >Date: Mon, Jun 12, 2000, 11:23 AM > > Here is my situation: > > We use authentication very similar to what is demonstrated > in the manual. We send a 401 header to pop up the login > dialog then we take that information and query a mysql > database to determine if the login is valid. > > To get into the site, the user is taken to a file: login.php3. > The only thing in that file is a call to my master login > function that validates the ID/PW information, determines > what type of user it is and directs them to the proper place > (via a header() call). If the information is incorrect, the > function returns and the page then displays an error. > In each page of the password protected section of the site, > I call a different function that just validates the ID/PW and > boots the user out if it is not correct. The problem I'm > experiencing is more with the login.php3 and here it is: > > A user will go to that page and put in their ID/PW to log > in. The information is good and so they are allowed in. > They go about their business, finish up and close out the > browser. Now, someone different goes to the site and they > are taken to the login.php3 page. They do not have a > valid ID/PW and so after 3 tries, they are given the afore- > mentioned error message and click the back button to > go back to the previous menu. However, if that user then > clicks the forward button to return and see the error > message, the user is instead presented with the menu for > the user who previosuly logged in. It is as if the browser > caches the previous users authentication information. While > I do not know if this is the case, I do know that it is caching > something because this only happens when the browser is > not set up to check for new versions of a web page every visit. > If the browser is set up to check every time, this problem does > not occur. > > Since this is almost certainly a caching issue, I thought I'd > be able to nip the problem in the bud by sending the > following headers right before I send the 401 authentication > header: > > header("Pragma: no-cache"); > header("Cache-Control: no-cache, must-revalidate"); > header("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT"); > header("Expires: Mon, 26 Jul 1997 05:00:00 GMT"); > > However, that did not solve my problem and I'm not sure why. > Has anyone ever experienced something like this? Does any > one have any suggestions? > > Here is the sample code. Copy into their respective pages and > when the authentication dialog pops up, type in "bob" as the > user name. You will be taken to page two. Exit the browser. > Go back to page1.php3, but this time, type something else as > the user name. You will be given the message that you failed. > Click the back button then click the forward button. You will > now see the message that you are at page2, even though you > did not pass the auth. > > page1.php3 > <script language="php"> > > if(!isset($PHP_AUTH_USER)) { > Header("WWW-Authenticate: Basic realm=\"My Realm\""); > Header("HTTP/1.0 401 Unauthorized"); > if( $PHP_AUTH_USER == "bob" ) { > header( "location: ./page2.php3" ); > exit(); > > } > echo "You Failed!!\n"; > exit; > > } else { > header( "location: ./page2.php3" ); > exit(); > > } > > </script> > > page2.php3 > <script language="php"> > > echo "You made it to page 2!!<br>\n"; > > </script> > > > Any help would be most gratefully appreciated!! > > Chris > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#1643) next »