Re: log out user with 401

From: Date: Wed, 12 Jul 2000 08:10:30 +0000
Subject: Re: log out user with 401
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-6096@lists.php.net to get a copy of this message
On Tue, 11 Jul 2000, Jan Horsman wrote: > Hi > > The PHP manual says, "Both Netscape and Internet Explorer will clear the > local browser window's authentication cache for the realm upon receiving a > server response of 401. This can effectively "log out" a user, forcing them > to re-enter their username and password. Some people use this to "time out" > logins, or provide a "log-out" button." > > But if you pass a 401 to a netscape client already authed, netscape pops up > a window complaining that auth failed and asks the user if he wants to try > again. Is there any way to clear the auth cache without netscape popping up > this complaint? The manual is not entirely correct on this. If you send a 401 just once, thinking that the user is then 'logged off' and any following request with a username and password is the new logon, you get problems when the user is running IE4+. Internet Explorer simply tries again if it gets a 401 (and it has a username/password for the given realm). If that request (the second) also doesn't succeed, it will then pop up the username/password dialog, with the username _and_ password already filled in... What you could do is not simply send a 401, but also send a different realm string with each, _but_ IE5.5 has a problem with that, as it doesn't automatically send a username/password with each request. This means that users using IE5.5 then must 'logon' for each request, not very nice :) Then there's netscape which I found out has another problem with this approach. If you send a 401 for a user, on netscape you will get a popup for a new username/password. Now if you press cancel on that popup, the page won't load, but you're also not logged off, all subsequent requests by Netscape are still made with the username/password you already had. What this means is that the server can't know if you really are logged off... So, if you want to have some sort of logon/off functionality while using basic authentication, you'll need to use something like sessions. e.g. Keep a session id, with a user assigned to it, in (shared) memory for as long as the user is logged on. When you want the user to log off, simply remove the session. This means that the logon/off is now not 'simulated' using Basic Authentication tricks, but done with sessions, which do not depend on browser behaviour. Do backup the session with the basic authentication, check that the username corresponds with the user for the session and that the password is correct. As for the second question, every time you send a 401 Authorisation required, you should expect the browser to display a login dialog and possibly an error message too. So there's no way to clear the auth cache on a browser without that message. But if you want to logoff somebody, you don't need to do that, only when he/she tries to logon again. regards, Auke van Slooten http://www.muze.nl/

« previous php.general (#6096) next »