RE: [PHP] WAYS OF AUTHENICATION - open discussion
| From: | MR | Date: | Sun, 05 Nov 2000 00:21:45 +0000 |
| Subject: | RE: [PHP] WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23746@lists.php.net to get a copy of this message | ||
Siim Einfeldt aka Itpunk ...
>
> I`m interested in different ways of authentication, their plusses and
> minuses.
I and my project group were discussing what authentification method we would use for the web we were
working in.
The client (that guy that needs that web done NOW), proposed LDAP as authentication method. You
know, LDAP is the thing that ISP's
use for every authentication of any of their servers... ISP authentification, pop or smtp
authentication, FTP autentication, web
authenticacion (of course), even wap authentication, or whatever authentication...
You may know, LDAP works as this... the POP server (for example) gets an incomming connection, gets
login and password. And the POP
server thinks "hey, i'm gonna pass this login & password to the LDAP server, he knows
if this user can access me"
Finnaly, LDAP was tought to be much more than we needed, and it would have taken a lot of time to
prepare and program.
The client wanted HIS web to be done as quick as possible, so we decided to use the simple way...
COOKIES.
The user is authenticated at the very beginning of each PHP page. If the posted (or cookie!)login
& password doesn't match the login
& password in the database we use, the system returns an authentication error... otherwise, the
user is accepted.
Simple, and very quick to implement with the wonderful INCLUDE() function.
Ah, the code does use a user & password when loading the login & password from the oracle
database... (they are not encrypted any
way!!) the only thing is that the final user just cannot see any of the php code, you know, he
wouldn't ever know the password for
the database.
My god, using that simple cookies is SO quick...