Re: Security question (newbe)

From: Date: Thu, 19 Oct 2000 03:16:35 +0000
Subject: Re: Security question (newbe)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-21044@lists.php.net to get a copy of this message
At 02:09 AM 18/10/2000, you wrote:
Please don't crucify me for this, I have one page that requires a login, as it stands now, the login is a PHP page that redirects the user to the admin page. The admin page uses 2 frames, a navigation frame and a main. Also, as it stands now, you can simply go to the admin page directly, bypassing the login.... this of course is bad.... Question1: which method do I use to combat this... Sessions, an external variable in a separate file, cookies, or some other method? Question2: Where can I find a good tutorial for the method you recommend?
Do you have the ability to use .htaccess instead of a php auth ? using .htaccess is a simple way to bring up a username/password box which protects an entire directory. So if you had a directory called admin, and protect the admin directory using .htaccess, ANY files requested from within the admin directory will require the user to have logged in. Once they have logged in, they can access all files in there. Otherwise, I would imagine that you would have to set a cookie, and each page you want protected needs to check to see if the cookie is still there, otherwise it wont show. Chris -
      Chris Aitken - Webmaster/Database Designer - IDEAL Internet
email: chris@ideal.net.au phone: +61 2 4628 8888 fax: +61 2 4628 8890
            --------------------------------------------
      Unix -- because a computer's a terrible thing to waste!


« previous php.general (#21044) next »