Re: clear HTTP authentication data ?
| From: | Peter Troll | Date: | Sat, 06 Jan 2001 22:28:07 +0000 |
| Subject: | Re: clear HTTP authentication data ? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-33057@lists.php.net to get a copy of this message | ||
Hi,
Thanks for the tip. It works indeed - it's just that a pop-up appears: "Authorization
failed. Retry ?". I would like to avoid this so that customers don't get such messages and
that lof-off is completely transparent to them. That's what I get with Netscape anyway. Opera
didn't understand the HTTP request. I am going to experiment a bit.
Meanwhile, Mukul Sabharwal has posted a very useful tip which works: if you want to access
information in a secured directory by way of script, you can fopen() like this:
http://username:password@www.mystuff.com/protected
This way I can authenticate users against, say, a mySQL DB and if their credentials are OK, give
them access to protected files they request. That simplifies things because:
- users don't have to know where the files they request are actually stored
- only 1 user is required in the passwd database
Regards,
-----------------------------------------------
This can be done by denying access to the user - simply create a page that
returns "HTTP/1.0 401 Unauthorized" in the headers. The next time a
protected page on the site is visited, it should require re-auth.
I've never tested this but I've heard it talked about; keep us updated if
you have any problems.
Toby Butzon
[ criticism spurs improvement ]