Re: Re: Authorization and...
| From: | Philip Hallstrom | Date: | Wed, 06 Dec 2000 22:47:56 +0000 |
| Subject: | Re: Re: Authorization and... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-28996@lists.php.net to get a copy of this message | ||
If you're not super concerned that they've logged you could do something
like this:
- on the first page, look them up in a database. If they match, set some
sort of hash in a cookie that indicates they have authenticated...
something like:
$cookieHash = md5($username . "somesecretkey");
- on all the other pages just check to make sure that the username
supplied via $PHP_AUTH_USER hashed with the above matches the hash of the
cookie.
That would save you a database hit on each page, but isnt' as secure. You
could also add some other data to the hash such as the weekday and hour
(ie "Wednesday 14") and check against that. If it's not valid, make
another call to the database. This would at least stop someone who stole
the cookie after an hour..
-philip
On Wed, 6 Dec 2000, Robert Ludvik wrote:
> > well copy that code to all those pages :) make sense ?
>
> this means that it will check for username and passwd for every additional site
> - 20 sites => 20 checkings to db. i thought of that but it seems a waste of
> resources (time?) to me.
>
> > if your using
> > $PHP_AUTH_USER
> > $PHP_AUTH_PW
> > those variables will be automatically carried to all the pages, just
> > check if their correct. I do this method, it works great,
>
> i've read Chapter 16. in PHP Manual - could work :)
>
> > else print
> > echo "Hey dumbass get it together";
> > exit();
>
> :))
> thnx
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>