Re: WWW-authenticate
| From: | Jason Lavigne | Date: | Sat, 02 Dec 2000 06:47:02 +0000 |
| Subject: | Re: WWW-authenticate | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-28252@lists.php.net to get a copy of this message | ||
That would not be a concern because the person that can see the URL in the
address bar is the person who logged in. The other option would be to send a
request directly from PHP for that user to the web server on a system level
thus giving the user access to the directory with out logging in a second
time. But doing this as far as I know would require PHP code to communicate
to the web server via HTTP. This code does exist (a class available on :
http://phpclasses.upperdesign.com) but the class
does not take in to account
authencation (I have modified the class to do so, but I can not pass the
code out cause I did not write it, I just modified it). So by far the
easiest way for Mike Mike to do it is by my example but if there is a better
way for him to do it without trying to fix a class that he did not write, I
am all ears.
Jay
----- Original Message -----
From: "Toby Butzon" <php-lists@imawebdesigner.com>
To: "Jason Lavigne" <jlavigne@stonecroft.net>; "Mike Mike"
<hatchman2000@yahoo.com>
Cc: <php-general@lists.php.net>
Sent: Friday, December 01, 2000 1:09 PM
Subject: Re: [PHP] WWW-authenticate
> You might want to be cautious about using this approach - I believe doing
so
> can leave the user/pass combo clearly exposed in the address bar.
>
> Toby Butzon
>
>
> ----- Original Message -----
> From: "Jason Lavigne" <jlavigne@stonecroft.net>
> To: "Mike Mike" <hatchman2000@yahoo.com>
> Cc: <php-general@lists.php.net>
> Sent: Saturday, December 02, 2000 12:57 AM
> Subject: Re: [PHP] WWW-authenticate
>
>
> : No problem :)
> :
> : Jay
> :
> : ----- Original Message -----
> : From: "Mike Mike" <hatchman2000@yahoo.com>
> : To: "Jason Lavigne" <jlavigne@stonecroft.net>
> : Sent: Friday, December 01, 2000 12:56 PM
> : Subject: Re: [PHP] WWW-authenticate
> :
> :
> : >
> : > That works!!
> : > Thank you Jay
> : >
> : > --- Jason Lavigne <jlavigne@stonecroft.net> wrote:
> : > > Redirect after login to this type of URL,
> : > >
> : > >
> : > http://username:password@yourdomain.com/secure_user_dir
> : > >
> : > > Jay
> : > >
> : > > ----- Original Message -----
> : > > From: "Mike Mike" <hatchman2000@yahoo.com>
> : > > To: <php-general@lists.php.net>
> : > > Sent: Friday, December 01, 2000 12:31 PM
> : > > Subject: [PHP] WWW-authenticate
> : > >
> : > >
> : > > > Greetings everyone,
> : > > > I have created a username/password form which when
> : > > a
> : > > > user submits their username password, It takes
> : > > them to
> : > > > their own secure .htaccess directory. I was
> : > > wondering
> : > > > if there was a way to take the $username and
> : > > $password
> : > > > from the php form that they submitted and put it
> : > > in
> : > > > the WWW-authenticate value so the second popup
> : > > window
> : > > > doesn't appear thats created by apache's
> : > > > username/password form.
> : > > > Is that possible?
> : > > > Thank you
> : > > > --Mike
> : > > >
> : > > >
> : > > > __________________________________________________
> : > > > Do You Yahoo!?
> : > > > Yahoo! Shopping - Thousands of Stores. Millions of
> : > > Products.
> : > > > http://shopping.yahoo.com/
> : > > >
> : > > > --
> : > > > PHP General Mailing List (http://www.php.net/)
> : > > > To unsubscribe, e-mail:
> : > > php-general-unsubscribe@lists.php.net
> : > > > For additional commands, e-mail:
> : > > php-general-help@lists.php.net
> : > > > To contact the list administrators, e-mail:
> : > > php-list-admin@lists.php.net
> : > > >
> : > >
> : >
> : >
> : > __________________________________________________
> : > Do You Yahoo!?
> : > Yahoo! Shopping - Thousands of Stores. Millions of Products.
> : > http://shopping.yahoo.com/
> : >
> :
> :
> : --
> : PHP General Mailing List (http://www.php.net/)
> : To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> : For additional commands, e-mail: php-general-help@lists.php.net
> : To contact the list administrators, e-mail: php-list-admin@lists.php.net
> :
> :
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>