Re: password auth with php 4.03p1
| From: | Ignacio Vazquez-Abrams | Date: | Sat, 18 Nov 2000 02:35:59 +0000 |
| Subject: | Re: password auth with php 4.03p1 | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-26012@lists.php.net to get a copy of this message | ||
On Fri, 17 Nov 2000 scottrus@ipass.net wrote:
> All -
>
> I have php password authentication working but not 100% the way I want. My problem is when
> users cancel
> the login process. Here is my script fragment:
>
> 00
> 01 if(!isset($PHP_AUTH_USER)) {
> 02 // user hit the cancel button
> 03 header("WWW-Authenticate: Basic realm=\"my site\");
> 04 header("HTTP/1.0 401 Unauthorized");
> 05 exit;
> 06 } else {
> 07 // verify userid/passwd
> 08 if (userauth($PHP_AUTH_USER,$PHP_AUTH_PW != 1) {
> 09 header("WWW-Authenticate: Basic realm=\"my site\");
> 10 header("HTTP/1.0 401 Unauthorized");
> 11 exit;
> 12 }
> 13 }
> 14
>
> This is basically what you find in the php manual under the subject of php HTTP auth. The
> problem for me
> is that when the user cancels they get a 'Page Contains No Data' response at the
> browser (NS4.x). I
> have 'ErrorDocument 403 /error_docs/403.html' defined in my apache httpd.conf but it
> never seems to get
> that far when the cancel button is pressed. If I insert a header("HTTP/1.0 403");
> just after lines 05
> and 10 then the user login fails without ever getting prompted.
>
> My best guess is that php is sending the 403 header along with the 401 headers. Any suggestions
> how to
> get this working?
>
Try putting an include(".../403.html") after lines 4 and 10.
It's not sending the 403 AND 401 headers, it's send the 403 INSTEAD OF
401, which is why it's failing.
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>