RE: [PHP] WAYS OF AUTHENICATION - open discussion

From: Date: Wed, 08 Nov 2000 15:26:02 +0000
Subject: RE: [PHP] WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-24326@lists.php.net to get a copy of this message
<? global $HTTP_POST_VARS, $HTTP_SERVER_VARS; if (!empty($HTTP_POST_VARS) & !strstr($HTTP_SERVER_VARS["HTTP_REFERER"],$HTTP_SERVER_VARS["HTTP_HOST"])) { header("Location: /error_docs/badcgi.html"); exit; } ?> >This code bit first checks to see if post data was sent and if so that the >contents of HTTP_REFERER are in the HTTP_HOST var. If they're not then this post >came from another site and it should be rejected. True, another way to make the things a bit more secure. >I don't cover get methods 'cause I want people to be able to bookmark get method >docs without a hassle. As a result I don't take free from inputs using get and tend to >limit get method input to simple numeric args to make bounds checking easier. Well, Im not using GET methods at all. In my opinion its possible to do everything I need with POST method or am i very wrong? >Also, regarding user auth, I think the best way is to use basic browser authentication >through php. It's a bit more complex to write in some cases but it helps eliminate >people swiping the login form and trying to hack it to by pass the auth check. I think the word 'basic' says enough. I dont know, I havent used it myself, but I haven´t heard anything very good about it either. Cheers Siim Einfeldt

« previous php.general (#24326) next »