destroing $PHP_AUTH_USER and $PHP_AUTH_PASS
| From: | Martin A. Marques | Date: | Thu, 29 Jun 2000 20:26:55 +0000 |
| Subject: | destroing $PHP_AUTH_USER and $PHP_AUTH_PASS | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-3892@lists.php.net to get a copy of this message | ||
I have a piece of code that asks for a user name and password usin html 4.0's
www-authenticate header. The problem is that I cant unset the username and
password for a new authentification, if it fails. the code is like this:
<?
if (! isset($PHP_AUTH_USER)) {
// User doesn't exist. Encourage user to enter username and password.
Header("WWW-Authenticate: carga basica=\"Carga de datos\"");
Header("HTTP/1.0 401 Unauthorized");
echo "No se puede cargar datos si no es un usuario autorizado.\n";
exit;
}else{
$usuario=$PHP_AUTH_USER;
// encrypt password
$passfr=md5($PHP_AUTH_PASS);
$conn_id=ifx_pconnect("diario","informix","password");
// look if the username and password is in database.
$q_auth=sprintf("SELECT u_nombre,u_password FROM usuario
WHERE u_nombre=\"%s\" AND u_password=\"%s\" ",
$usuario,$passfr);
$q_id=ifx_query($q_auth,$conn_id);
$q_ar_auth=ifx_fetch_row($q_id);
if (! $q_ar_auth){
// user + pass is not in the database. destroy $PHP_AUTH_USER and reload
// index.php
unset($PHP_AUTH_USER);
header("location: index.php");
}else{
// destroy the password holding variable and redirect to diario.php
unset($PHP_AUTH_PASS);
header("Location: diario.php");
}
}
?>
Any idea?
--
"And I'm happy, because you make me feel good, about me." - Melvin Udall
-----------------------------------------------------------------
Martín Marqués email: martin@math.unl.edu.ar
Santa Fe - Argentina http://math.unl.edu.ar/~martin/
Administrador de sistemas en math.unl.edu.ar
-----------------------------------------------------------------