Re: log out user with 401
| From: | Auke van Slooten | Date: | Wed, 12 Jul 2000 08:10:30 +0000 |
| Subject: | Re: log out user with 401 | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-6096@lists.php.net to get a copy of this message | ||
On Tue, 11 Jul 2000, Jan Horsman wrote:
> Hi
>
> The PHP manual says, "Both Netscape and Internet Explorer will clear the
> local browser window's authentication cache for the realm upon receiving a
> server response of 401. This can effectively "log out" a user, forcing them
> to re-enter their username and password. Some people use this to "time out"
> logins, or provide a "log-out" button."
>
> But if you pass a 401 to a netscape client already authed, netscape pops up
> a window complaining that auth failed and asks the user if he wants to try
> again. Is there any way to clear the auth cache without netscape popping up
> this complaint?
The manual is not entirely correct on this. If you send a 401 just once,
thinking that the user is then 'logged off' and any following request with
a username and password is the new logon, you get problems when the user
is running IE4+. Internet Explorer simply tries again if it gets a 401
(and it has a username/password for the given realm). If that request (the
second) also doesn't succeed, it will then pop up the username/password
dialog, with the username _and_ password already filled in...
What you could do is not simply send a 401, but also send a different
realm string with each, _but_ IE5.5 has a problem with that, as it doesn't
automatically send a username/password with each request. This means that
users using IE5.5 then must 'logon' for each request, not very nice :)
Then there's netscape which I found out has another problem with this
approach. If you send a 401 for a user, on netscape you will get a popup
for a new username/password. Now if you press cancel on that popup, the
page won't load, but you're also not logged off, all subsequent requests
by Netscape are still made with the username/password you already had.
What this means is that the server can't know if you really are logged
off...
So, if you want to have some sort of logon/off functionality while using
basic authentication, you'll need to use something like sessions. e.g.
Keep a session id, with a user assigned to it, in (shared) memory for as
long as the user is logged on. When you want the user to log off, simply
remove the session. This means that the logon/off is now not 'simulated'
using Basic Authentication tricks, but done with sessions, which do not
depend on browser behaviour.
Do backup the session with the basic authentication, check that the
username corresponds with the user for the session and that the password
is correct.
As for the second question, every time you send a 401 Authorisation
required, you should expect the browser to display a login dialog and
possibly an error message too. So there's no way to clear the auth cache
on a browser without that message. But if you want to logoff somebody,
you don't need to do that, only when he/she tries to logon again.
regards,
Auke van Slooten
http://www.muze.nl/