Re: password auth with php 4.03p1

From: Date: Sat, 18 Nov 2000 18:23:32 +0000
Subject: Re: password auth with php 4.03p1
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-26070@lists.php.net to get a copy of this message
On 18-Nov-00 scottrus@ipass.net wrote: > On Fri, Nov 17, 2000 at 09:35:59PM -0500, Ignacio Vazquez-Abrams wrote: >> Try putting an include(".../403.html") after lines 4 and 10. >> >> It's not sending the 403 AND 401 headers, it's send the 403 INSTEAD OF >> 401, which is why it's failing. > > This works but is not the result I'm after. I want to have apache handle the > 403 and offer > up the document. The reason I want this is because I auto_append my standard > header to everthing off > the site. If I use an include() as you suggest things get ugly quick. > Specifically, the document the > user requested has headers sent (the 401/Passwd Auth) and then the included > document wants to send > headers yet again (because of the auto_append). > > The best solution would be to have apache just handle the whole 403 reply, > so why doesn't it? > > The second best solution would be to use a header("Location: > /error_docs/403.html); which I could live > with but again, the header gets sent right on top of the 401 header request > and the user never sees the > password prompt, they just get redirected to the /error/403.html doc. > > -- Scott > Why send the 403? Instead i "refresh" them back to a safe page : function authheader($realm) { Header('WWW-authenticate: basic realm="'.$realm .'"'); Header('HTTP/1.0 401 Unauthorized'); echo "\n\n"; echo '<META HTTP-EQUIV="Refresh" CONTENT="1; URL='.SITEHOME.'/">'; } function authuser($realm) { global $PHP_AUTH_USER, $PHP_AUTH_PW; if (! (isset($PHP_AUTH_USER)) ) { authheader($realm); exit; } if (! (checklogin($realm)) ) { authheader($realm); echo '<CENTER>Failed Login'; exit; } } -- Don Read dread@texas.net -- The problem with people who have no vices is that you can be sure they're going to have some pretty annoying virtues.

« previous php.general (#26070) next »