Re: PHP authentication
| From: | Richard Lynch | Date: | Tue, 12 Dec 2000 18:46:25 +0000 |
| Subject: | Re: PHP authentication | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29932@lists.php.net to get a copy of this message | ||
> website login with HTML form ->
> look up in htaccess-file ->
This is going to be problematic -- An htaccess file is generally designed
for use with HTTP Authentication which has that popup window, not an HTML
form.
I *guess* you could read the htaccess file, search for the user, compare the
encryption of their password and then go on...
But at that point, you might as well keep your usernames/passwords in MySQL.
> lookup in MySQL dB ->
> set header with USER/PASS ->
No.
It just doesn't work that way.
In HTTP Authentication, the BROWSER gets their username/password, and
presents it to HTTP on each page hit. At *NO* time does the server send the
username/password *back* to the browser. It just ain't in the browser code
nor HTTP spec to work that way.
> do stuff ->
> logout !
This is also a bit more complicated than you think: There is no command the
server can send to the browser to tell it to stop presenting
username/password. You'll need to store some sort of data in your MySQL
database to keep track of who's "logged in" and who's not -- And you'll
need
to write some PHP code to do the right thing based on what's in the
database.
I suggest you look at the code archives http://php.net/links.php and at
packages such as PHPLib that provide a user-authentication codebase.