RE: [PHP] destroing $PHP_AUTH_USER and $PHP_AUTH_PASS
| From: | Rasmus Lerdorf | Date: | Sat, 01 Jul 2000 01:33:22 +0000 |
| Subject: | RE: [PHP] destroing $PHP_AUTH_USER and $PHP_AUTH_PASS | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-4207@lists.php.net to get a copy of this message | ||
On Fri, 30 Jun 2000, Daevid Vincent wrote:
> > Sorry for the fast send. made some mistakes in typing. It's $PHP_AUTH_PW
> > wherever you see $PHP_AUTH_PASS. My mistake, should have double
> > checked the
> > mail before sending.
> >
> > The problem, still is that when the authentification is wrong, I want to
> > unset $PHP_AUTH_USER, and PHP isn't doing it.
> >
> > Am I doing something wrong?
>
> I've never been able to get this to work either.
>
> I believe it has to do with the browser 'caching' it in memory so you're not
> prompted for each subdir or whatever. The only suggestion I have is to tell
> the user to close the browser (actually, ALL occurences of it) and re-open
> it again to clear it out. Sucks I know, but that's the only thing that's
> worked so far. and I tried to set them to null, to "", to unset(), etc...
PHP is unsetting it, but on the next request your browser sends it again,
and PHP sets the variables again. Think of them as cookies you can't
delete. Would be nice if there was some way to tell the browser to clear
its authentication cache, but there isn't. It's a deficiency in the
browsers.
-Rasmus