RE: [PHP3] Re: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (a nd PHP?)

From: Date: Mon, 12 Jun 2000 19:12:15 +0000
Subject: RE: [PHP3] Re: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (a nd PHP?)
Groups: php.general 
Request: Send a blank email to php-general+get-1647@lists.php.net to get a copy of this message
> Are you using the same machine to log in with after quitting? Yes. > You shouldn't experience this on two separate machines with > two separate logins. Possibly, but this is largely moot as I'm trying to make it so that it doesn't happen on the same machine, as above. > Most (all?) browsers cache the username and password. Most > of them also remove them when the user quits the browser. This is the expected behaviour. And, for the most part, is what is happening. Each time the user logins in successfully, totally exits the browser then comes back in, they are prompted with the authentication dialogue box. However, if at this point, they fail to log in, they can simply click the back button then the forward button and they see the next page as if they logged in. > I don't believe that this caching is the same as the regular web page > caching, so I don't think the pragma headers will help. It isn't, unfortunately. > What has been suggested on the list before is to set up your > authentication scheme using some kind of timestamp in the > realm. You may want to search the archives for more info > about that. This is not an option. On every page, we run our log in routine so if the user has already logged in, the function will pass right through. However, if someone bookmarks a permissions only page and tries to jumpt straight to it, they will be required to log in. If I did the above, the realm would change every minute or second and the user will be required to log in for every page. At this point you might be thinking "Well, if they require Auth on every page, this is not an issue as the user will be prompted for login at every page". This is true. However, the person doing this can continue to press the back then forward button to see that next page. This is a serious security issue in that I can go to any library terminal, go to a website that has both a secure section and is using PHP and go right in and see what the previous user did. Now, I don't know if this is a security issue with HTTP or PHP, but it's still there regardless. I'm hoping I can find some way around this. Chris

« previous php.general (#1647) next »