Re: Security question (newbe)
| From: | Chris Aitken | Date: | Thu, 19 Oct 2000 03:16:35 +0000 |
| Subject: | Re: Security question (newbe) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-21044@lists.php.net to get a copy of this message | ||
At 02:09 AM 18/10/2000, you wrote:
Please don't crucify me for this, I have one page that requires a login, as it stands now, the login is a PHP page that redirects the user to the admin page. The admin page uses 2 frames, a navigation frame and a main. Also, as it stands now, you can simply go to the admin page directly, bypassing the login.... this of course is bad.... Question1: which method do I use to combat this... Sessions, an external variable in a separate file, cookies, or some other method? Question2: Where can I find a good tutorial for the method you recommend?Do you have the ability to use .htaccess instead of a php auth ? using .htaccess is a simple way to bring up a username/password box which protects an entire directory. So if you had a directory called admin, and protect the admin directory using .htaccess, ANY files requested from within the admin directory will require the user to have logged in. Once they have logged in, they can access all files in there. Otherwise, I would imagine that you would have to set a cookie, and each page you want protected needs to check to see if the cookie is still there, otherwise it wont show. Chris -
Chris Aitken - Webmaster/Database Designer - IDEAL Internetemail: chris@ideal.net.au phone: +61 2 4628 8888 fax: +61 2 4628 8890
--------------------------------------------
Unix -- because a computer's a terrible thing to waste!