RE: [PHP] WAYS OF AUTHENICATION - open discussion
| From: | Siim Einfeldt aka Itpunk | Date: | Wed, 08 Nov 2000 15:26:02 +0000 |
| Subject: | RE: [PHP] WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-24326@lists.php.net to get a copy of this message | ||
<?
global $HTTP_POST_VARS, $HTTP_SERVER_VARS;
if (!empty($HTTP_POST_VARS) &
!strstr($HTTP_SERVER_VARS["HTTP_REFERER"],$HTTP_SERVER_VARS["HTTP_HOST"])) {
header("Location: /error_docs/badcgi.html");
exit;
}
?>
>This code bit first checks to see if post data was sent and if so that
the
>contents of HTTP_REFERER are in the HTTP_HOST var. If they're not then
this post
>came from another site and it should be rejected.
True, another way to make the things a bit more secure.
>I don't cover get methods 'cause I want people to be able to bookmark get
method
>docs without a hassle. As a result I don't take free from inputs using
get and tend to
>limit get method input to simple numeric args to make bounds checking
easier.
Well, I
m not using GET methods at all. In my opinion its possible to do
everything I need with POST method or am i very wrong?
>Also, regarding user auth, I think the best way is to use basic browser
authentication
>through php. It's a bit more complex to write in some cases but it helps
eliminate
>people swiping the login form and trying to hack it to by pass the auth
check.
I think the word 'basic' says enough. I dont know, I havent used it
myself, but I haven´t heard anything very good about it either.
Cheers
Siim Einfeldt