PHP username/password and POST forms
| From: | Damian Sobieralski | Date: | Sat, 04 Nov 2000 00:36:12 +0000 |
| Subject: | PHP username/password and POST forms | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-23664@lists.php.net to get a copy of this message | ||
I'm a PHP newbie working on getting an effective simple
authentication page to work. I have scoured the Net and listserv archives
searching for an example of an authentication program but to no avail. In
fact, I really like the "Professional PHP Programming" book and although
it gives a nifty shopping cart example, it does not cover the user
authentication issue I am seeking.
Firstly, yes I am using simple techniques but I am more interested in the
concepts than cookie versus URL session id passing (unless an idea is by
using a cookie I can fix this). In fact I have to imagine this is purely theoretical
thusly this would apply even if using Perl or C for the processing.
Reality check/verification:
I obviously chose the POST method of form submittal because GET passes them
via the URL and this will show up on the browser's location bar (trying to
disable the location bar is not an option for me as that seems like too much a hack).
------------------------------------------------------
<?php
header("Pragma: no-cache");
header("Cache-Control: no-cache");
if (empty($username))
{
?>
<center>
Type in your e-mail userid and password<br>
<form action= <?php print $PHP_SELF; ?> method="post">
Username: <input type=text name=username size=10><p>
Password: <input type=password name=userpass size=10>
<p>
<INPUT TYPE=submit VALUE=SUBMIT ></FORM>
</center>
<?php
}
else
{
if (verify_usernamepassword($username, $userpass))
{
$sessionid = getnewsessionid();
add_session_to_table($sessionid, $username);
print "you made it tuf' guy! <p>\n";
remove_session_from_table($sessionid);
?>
<a href=http://www.yahoo.com> Next page </a>
<?php
}
else
{
print "wrong buddy <p>\n";
}
}
?>
The problem I get is
1) user types in correct username and password. Hits submit
2) User gets an okie dokie page. Logs them in then out.
3) User goes past initial okie dokie page resulting from post (www.yahoo.com in this case)
4) User hits the back button. The browser asks if I want to repost the
data. I hit reload. Viola, I am back in the system
I have found a few posts asking about this "persistent" post caching but
no solutions. Let me go one step beyond as maybe this is the wrong
approach to take. Could someone show me a method that works without this
"feature"? Best I could figure out on my own is that on the login form is an
embedded pre session id. When the user submits the form to be verified
this sessionid has a creation date associated with it. If 20 seconds
pass since the login form was generated and the user hits <submit> they
get a message of session expired. However, this still does not address
if a user logs in, logs out and a kung-fu master takes over their PC (with
Netscape still open) and hits the back button all within 20 seconds.
If it was not for this POST persistence this would be easy. I have to
think it is easy and I just do not know what I am doing :-)