RE: [PHP3] Re: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (a nd PHP?)
| From: | Boget, Chris | Date: | Mon, 12 Jun 2000 19:12:15 +0000 |
| Subject: | RE: [PHP3] Re: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (a nd PHP?) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-1647@lists.php.net to get a copy of this message | ||
> Are you using the same machine to log in with after quitting?
Yes.
> You shouldn't experience this on two separate machines with
> two separate logins.
Possibly, but this is largely moot as I'm trying to make it so that
it doesn't happen on the same machine, as above.
> Most (all?) browsers cache the username and password. Most
> of them also remove them when the user quits the browser.
This is the expected behaviour. And, for the most part, is what is
happening. Each time the user logins in successfully, totally exits
the browser then comes back in, they are prompted with the
authentication dialogue box. However, if at this point, they fail
to log in, they can simply click the back button then the forward
button and they see the next page as if they logged in.
> I don't believe that this caching is the same as the regular web page
> caching, so I don't think the pragma headers will help.
It isn't, unfortunately.
> What has been suggested on the list before is to set up your
> authentication scheme using some kind of timestamp in the
> realm. You may want to search the archives for more info
> about that.
This is not an option. On every page, we run our log in routine
so if the user has already logged in, the function will pass right
through. However, if someone bookmarks a permissions only
page and tries to jumpt straight to it, they will be required to log
in. If I did the above, the realm would change every minute or
second and the user will be required to log in for every page. At
this point you might be thinking "Well, if they require Auth on
every page, this is not an issue as the user will be prompted for
login at every page". This is true. However, the person doing
this can continue to press the back then forward button to see
that next page. This is a serious security issue in that I can go
to any library terminal, go to a website that has both a secure
section and is using PHP and go right in and see what the previous
user did. Now, I don't know if this is a security issue with HTTP
or PHP, but it's still there regardless. I'm hoping I can find some
way around this.
Chris