RE: [PHP] Insecurity with PHP authorization
| From: | Mark Roedel | Date: | Tue, 07 Aug 2001 13:23:25 +0000 |
| Subject: | RE: [PHP] Insecurity with PHP authorization | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-61610@lists.php.net to get a copy of this message | ||
> -----Original Message-----
> From: Stefen Lars [mailto:stefenlars@hotmail.com]
> Sent: Tuesday, August 07, 2001 3:03 AM
> To: php-general@lists.php.net
> Subject: [PHP] Insecurity with PHP authorization
>
>
> I do realize that if I were to place a .htaccess file in the
> root of the intranet server, I could prevent the above from
> happening, but then I loose the advantage of having the users
> profile in a database, where a user can easily change her
> password. Allowing a web user to edit a password in the
> .htaccess file poses more problems than it solves, especially
> as it certainly could occur that more than one persons wants to
> edit his password simultaneously.
If you control the server, have you considered something along the lines
of mod_auth_mysql (which would allow you to place a .htaccess file that
authenticates using the information stored in your mysql database)?
I've used it on a few projects here with good results.
You can pick up a copy from the "contrib" downloads at mysql.com.
---
Mark Roedel (roedelm@letu.edu) | "There cannot be a crisis next week.
Systems Programmer / WebMaster | My schedule is already full."
LeTourneau University | -- Henry Kissinger