Re: PHP authentication

From: Date: Tue, 12 Dec 2000 18:46:25 +0000
Subject: Re: PHP authentication
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29932@lists.php.net to get a copy of this message
> website login with HTML form -> > look up in htaccess-file -> This is going to be problematic -- An htaccess file is generally designed for use with HTTP Authentication which has that popup window, not an HTML form. I *guess* you could read the htaccess file, search for the user, compare the encryption of their password and then go on... But at that point, you might as well keep your usernames/passwords in MySQL. > lookup in MySQL dB -> > set header with USER/PASS -> No. It just doesn't work that way. In HTTP Authentication, the BROWSER gets their username/password, and presents it to HTTP on each page hit. At *NO* time does the server send the username/password *back* to the browser. It just ain't in the browser code nor HTTP spec to work that way. > do stuff -> > logout ! This is also a bit more complicated than you think: There is no command the server can send to the browser to tell it to stop presenting username/password. You'll need to store some sort of data in your MySQL database to keep track of who's "logged in" and who's not -- And you'll need to write some PHP code to do the right thing based on what's in the database. I suggest you look at the code archives http://php.net/links.php and at packages such as PHPLib that provide a user-authentication codebase.

« previous php.general (#29932) next »