Re: MySQL/PHP/htaccess auth system
| From: | php3 at developersdesk dot com | Date: | Sat, 09 Dec 2000 07:12:47 +0000 |
| Subject: | Re: MySQL/PHP/htaccess auth system | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-29464@lists.php.net to get a copy of this message | ||
Addressed to: Chris Aitken <chris@ideal.net.au>
php-general@lists.php.net
** Reply to note from Chris Aitken <chris@ideal.net.au> Fri, 08 Dec 2000 17:09:05 +1100
> I have recently written a system which does the following. Im not
> sure if this is sound security wise, or even coding wise, but it
> works a treat for me..... Plus it controls the site as to what pages
> different users can access based on a level number system
>
>
> I use htaccess to simply auth users into the site (I like doing it
> this way because it protects the entire directory). And the index
> PHP page does 2 things. Queries the database which lists all known
> usernames, and their level of access. Then it takes those 2 figures
> and sets them as cookies.
>
> At this stage its authenticated the user, and set their username and
> access level for use later.
>
> Then I simply have a line in each PHP file I write like
> auth_user($accesslevel,10); This calls the auth_user function (below)
> and tells it what level the user has been set (from the cookie) and
> what level is required for the user to access the page.
>
> The function simply compares the level of access set to the user to
> the level of access required for that page, and if its okay (the
> user has higher or equal access) then it continues, otherwise it
> reports an error page.
>
> Like I said, I dont know if a system like this is any good
> structurally, but comments on its concept would be appreciated. I
> can put the code in if you want, but I wanted to keep it simple to
> start with.
I can see a couple of holes.
1. If cookies are turned off, you can't access the site.
2. A determined user can change their access level by editing what the
access level cookie returnes.
As far as keeping track of the user name, since you are using basic
authentication, you can get the user name from $REMOTE_USER on any page
they authenticate.
I would suggest you just go to the database on each page using
$REMOTE_USER to get the access level, and drop the cookies.
Rick Widmer
Internet Marketing Specialists
http://www.developersdesk.com