Re: PHP username/password and POST forms
| From: | jeremy brand | Date: | Sat, 04 Nov 2000 00:49:34 +0000 |
| Subject: | Re: PHP username/password and POST forms | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23665@lists.php.net to get a copy of this message | ||
http://www.nirvani.net/software/j-sessions-1.0.0-pre1/
It is small enough, that you should be able to easily walk through it
and understand. Maybe it will help you emplement your own, or modify it
to your needs, whatever makes sense for your application.
It is kind of a reference platform now, good for learning. The ideas
expressed in the software are my own -- what I'm saying is that other
session software may be different in architecture.
Hope this helps,
-jeremy brand
_______________________________________________________________________
GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9
_ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html
for more __
On Fri, 3 Nov 2000, Damian Sobieralski wrote:
> Date: Fri, 3 Nov 2000 19:36:12 -0500 (EST)
> From: Damian Sobieralski <dsobiera@smc.cc.mi.us>
> To: php-general@lists.php.net
> Subject: [PHP] PHP username/password and POST forms
>
>
> I'm a PHP newbie working on getting an effective simple
> authentication page to work. I have scoured the Net and listserv archives
> searching for an example of an authentication program but to no avail. In
> fact, I really like the "Professional PHP Programming" book and although
> it gives a nifty shopping cart example, it does not cover the user
> authentication issue I am seeking.
>
> Firstly, yes I am using simple techniques but I am more interested in the
> concepts than cookie versus URL session id passing (unless an idea is by
> using a cookie I can fix this). In fact I have to imagine this is purely theoretical
> thusly this would apply even if using Perl or C for the processing.
>
> Reality check/verification:
> I obviously chose the POST method of form submittal because GET passes them
> via the URL and this will show up on the browser's location bar (trying to
> disable the location bar is not an option for me as that seems like too much a hack).
>
> ------------------------------------------------------
> <?php
> header("Pragma: no-cache");
> header("Cache-Control: no-cache");
>
> if (empty($username))
> {
> ?>
> <center>
> Type in your e-mail userid and password<br>
> <form action= <?php print $PHP_SELF; ?> method="post">
> Username: <input type=text name=username size=10><p>
> Password: <input type=password name=userpass size=10>
> <p>
> <INPUT TYPE=submit VALUE=SUBMIT ></FORM>
> </center>
> <?php
> }
> else
> {
> if (verify_usernamepassword($username, $userpass))
> {
> $sessionid = getnewsessionid();
> add_session_to_table($sessionid, $username);
> print "you made it tuf' guy! <p>\n";
> remove_session_from_table($sessionid);
> ?>
> <a href=http://www.yahoo.com> Next page </a>
> <?php
> }
> else
> {
> print "wrong buddy <p>\n";
> }
> }
> ?>
>
> The problem I get is
>
> 1) user types in correct username and password. Hits submit
> 2) User gets an okie dokie page. Logs them in then out.
> 3) User goes past initial okie dokie page resulting from post (www.yahoo.com in this case)
> 4) User hits the back button. The browser asks if I want to repost the
> data. I hit reload. Viola, I am back in the system
>
> I have found a few posts asking about this "persistent" post caching but
> no solutions. Let me go one step beyond as maybe this is the wrong
> approach to take. Could someone show me a method that works without this
> "feature"? Best I could figure out on my own is that on the login form is an
> embedded pre session id. When the user submits the form to be verified
> this sessionid has a creation date associated with it. If 20 seconds
> pass since the login form was generated and the user hits <submit> they
> get a message of session expired. However, this still does not address
> if a user logs in, logs out and a kung-fu master takes over their PC (with
> Netscape still open) and hits the back button all within 20 seconds.
>
> If it was not for this POST persistence this would be easy. I have to
> think it is easy and I just do not know what I am doing :-)
>
>
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>