Re: spoofing HTTP auth
| From: | Jason Brooke | Date: | Wed, 27 Sep 2000 05:35:38 +0000 |
| Subject: | Re: spoofing HTTP auth | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-17654@lists.php.net to get a copy of this message | ||
send the username and password in the request in the standard format:
http://user:pass@hostname.domain.com/some/path/to/file
I think this is probably all your web browser does after you type in the
user and pass into the popup box anyway - but the http rfc/s will
confirm
jason
> Okay, I've read all I could find on the archive regarding HTTP auth,
and it
> seems we can't separate the pop-up box from the authentication,
because the
> pop-up box is part of the client, correct? But, what if PHP is the
client,
> that is, using fopen to open a url that requires http auth? Can I
somehow
> send a user name and pass to that URL.
>
> Here's the long version....
> I have a portal that authenticates a user and pass by attempting a
> connection to a Lotus Domino Server via POP3. This works.
(Beautifully, I
> might add.) This same user and pass is used to authenticate users
> connecting to other Notes resources on the same server. However, if I
link
> to the nsf files directly I get pop-up boxes. This is one problem I'd
like
> to solve by somehow authenticating in the background maybe? Other
issue is
> that there are notes resources such as calendars and todo lists that I
can
> get and use but directly in the portal, but again, only if the user
has been
> authenticated.
>
> Any suggestions, hints, or sympathy is welcome...
>
> Oh yeah, I already tried the don't use Notes method. Got that,
thanks....
>
> -David
>
> David Knape
> Web Application / Multimedia Developer
>
> dave@tkdave.com
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail:
php-list-admin@lists.php.net
>
>