Re: password auth with php 4.03p1

From: Date: Sat, 18 Nov 2000 03:47:00 +0000
Subject: Re: password auth with php 4.03p1
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-26013@lists.php.net to get a copy of this message
On Fri, Nov 17, 2000 at 09:35:59PM -0500, Ignacio Vazquez-Abrams wrote: > Try putting an include(".../403.html") after lines 4 and 10. > > It's not sending the 403 AND 401 headers, it's send the 403 INSTEAD OF > 401, which is why it's failing. This works but is not the result I'm after. I want to have apache handle the 403 and offer up the document. The reason I want this is because I auto_append my standard header to everthing off the site. If I use an include() as you suggest things get ugly quick. Specifically, the document the user requested has headers sent (the 401/Passwd Auth) and then the included document wants to send headers yet again (because of the auto_append). The best solution would be to have apache just handle the whole 403 reply, so why doesn't it? The second best solution would be to use a header("Location: /error_docs/403.html); which I could live with but again, the header gets sent right on top of the 401 header request and the user never sees the password prompt, they just get redirected to the /error/403.html doc. -- Scott > > On Fri, 17 Nov 2000 scottrus@ipass.net wrote: > > > All - > > > > I have php password authentication working but not 100% the way I want. My problem is when > > users cancel > > the login process. Here is my script fragment: > > > > 00 > > 01 if(!isset($PHP_AUTH_USER)) { > > 02 // user hit the cancel button > > 03 header("WWW-Authenticate: Basic realm=\"my site\"); > > 04 header("HTTP/1.0 401 Unauthorized"); > > 05 exit; > > 06 } else { > > 07 // verify userid/passwd > > 08 if (userauth($PHP_AUTH_USER,$PHP_AUTH_PW != 1) { > > 09 header("WWW-Authenticate: Basic realm=\"my site\"); > > 10 header("HTTP/1.0 401 Unauthorized"); > > 11 exit; > > 12 } > > 13 } > > 14 > > > > This is basically what you find in the php manual under the subject of php HTTP auth. The > > problem for me > > is that when the user cancels they get a 'Page Contains No Data' response at the > > browser (NS4.x). I > > have 'ErrorDocument 403 /error_docs/403.html' defined in my apache httpd.conf > > but it never seems to get > > that far when the cancel button is pressed. If I insert a header("HTTP/1.0 > > 403"); just after lines 05 > > and 10 then the user login fails without ever getting prompted. > > > > My best guess is that php is sending the 403 header along with the 401 headers. Any > > suggestions how to > > get this working? > > > > -- > Ignacio Vazquez-Abrams <ignacio@openservices.net> > -- Scott

« previous php.general (#26013) next »