RE: [PHP] WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 00:21:45 +0000
Subject: RE: [PHP] WAYS OF AUTHENICATION - open discussion
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-23746@lists.php.net to get a copy of this message
Siim Einfeldt aka Itpunk ... > > I`m interested in different ways of authentication, their plusses and > minuses. I and my project group were discussing what authentification method we would use for the web we were working in. The client (that guy that needs that web done NOW), proposed LDAP as authentication method. You know, LDAP is the thing that ISP's use for every authentication of any of their servers... ISP authentification, pop or smtp authentication, FTP autentication, web authenticacion (of course), even wap authentication, or whatever authentication... You may know, LDAP works as this... the POP server (for example) gets an incomming connection, gets login and password. And the POP server thinks "hey, i'm gonna pass this login & password to the LDAP server, he knows if this user can access me" Finnaly, LDAP was tought to be much more than we needed, and it would have taken a lot of time to prepare and program. The client wanted HIS web to be done as quick as possible, so we decided to use the simple way... COOKIES. The user is authenticated at the very beginning of each PHP page. If the posted (or cookie!)login & password doesn't match the login & password in the database we use, the system returns an authentication error... otherwise, the user is accepted. Simple, and very quick to implement with the wonderful INCLUDE() function. Ah, the code does use a user & password when loading the login & password from the oracle database... (they are not encrypted any way!!) the only thing is that the final user just cannot see any of the php code, you know, he wouldn't ever know the password for the database. My god, using that simple cookies is SO quick...

« previous php.general (#23746) next »