RE: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (and PHP?)

From: Date: Mon, 12 Jun 2000 21:17:44 +0000
Subject: RE: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (and PHP?)
Groups: php.general 
Request: Send a blank email to php-general+get-1659@lists.php.net to get a copy of this message
Can you send a URL so that I can see this happening? This is quite interesting :) (and very annoying) berber http://www.weberdev.com -----Original Message----- From: Boget, Chris [mailto:chris@wild.net] Sent: Monday, June 12, 2000 8:23 PM To: 'php-general@lists.php.net'; Php3 (E-mail) Subject: [PHP-GENERAL] *Serious* problems with HTTP_AUTH (and PHP?) Here is my situation: We use authentication very similar to what is demonstrated in the manual. We send a 401 header to pop up the login dialog then we take that information and query a mysql database to determine if the login is valid. To get into the site, the user is taken to a file: login.php3. The only thing in that file is a call to my master login function that validates the ID/PW information, determines what type of user it is and directs them to the proper place (via a header() call). If the information is incorrect, the function returns and the page then displays an error. In each page of the password protected section of the site, I call a different function that just validates the ID/PW and boots the user out if it is not correct. The problem I'm experiencing is more with the login.php3 and here it is: A user will go to that page and put in their ID/PW to log in. The information is good and so they are allowed in. They go about their business, finish up and close out the browser. Now, someone different goes to the site and they are taken to the login.php3 page. They do not have a valid ID/PW and so after 3 tries, they are given the afore- mentioned error message and click the back button to go back to the previous menu. However, if that user then clicks the forward button to return and see the error message, the user is instead presented with the menu for the user who previosuly logged in. It is as if the browser caches the previous users authentication information. While I do not know if this is the case, I do know that it is caching something because this only happens when the browser is not set up to check for new versions of a web page every visit. If the browser is set up to check every time, this problem does not occur. Since this is almost certainly a caching issue, I thought I'd be able to nip the problem in the bud by sending the following headers right before I send the 401 authentication header: header("Pragma: no-cache"); header("Cache-Control: no-cache, must-revalidate"); header("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT"); header("Expires: Mon, 26 Jul 1997 05:00:00 GMT"); However, that did not solve my problem and I'm not sure why. Has anyone ever experienced something like this? Does any one have any suggestions? Here is the sample code. Copy into their respective pages and when the authentication dialog pops up, type in "bob" as the user name. You will be taken to page two. Exit the browser. Go back to page1.php3, but this time, type something else as the user name. You will be given the message that you failed. Click the back button then click the forward button. You will now see the message that you are at page2, even though you did not pass the auth. page1.php3 <script language="php"> if(!isset($PHP_AUTH_USER)) { Header("WWW-Authenticate: Basic realm=\"My Realm\""); Header("HTTP/1.0 401 Unauthorized"); if( $PHP_AUTH_USER == "bob" ) { header( "location: ./page2.php3" ); exit(); } echo "You Failed!!\n"; exit; } else { header( "location: ./page2.php3" ); exit(); } </script> page2.php3 <script language="php"> echo "You made it to page 2!!<br>\n"; </script> Any help would be most gratefully appreciated!! Chris -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#1659) next »