RE: [PHP] Insecurity with PHP authorization

From: Date: Tue, 07 Aug 2001 13:23:25 +0000
Subject: RE: [PHP] Insecurity with PHP authorization
Groups: php.general 
Request: Send a blank email to php-general+get-61610@lists.php.net to get a copy of this message
> -----Original Message----- > From: Stefen Lars [mailto:stefenlars@hotmail.com] > Sent: Tuesday, August 07, 2001 3:03 AM > To: php-general@lists.php.net > Subject: [PHP] Insecurity with PHP authorization > > > I do realize that if I were to place a .htaccess file in the > root of the intranet server, I could prevent the above from > happening, but then I loose the advantage of having the users > profile in a database, where a user can easily change her > password. Allowing a web user to edit a password in the > .htaccess file poses more problems than it solves, especially > as it certainly could occur that more than one persons wants to > edit his password simultaneously. If you control the server, have you considered something along the lines of mod_auth_mysql (which would allow you to place a .htaccess file that authenticates using the information stored in your mysql database)? I've used it on a few projects here with good results. You can pick up a copy from the "contrib" downloads at mysql.com. --- Mark Roedel (roedelm@letu.edu) | "There cannot be a crisis next week. Systems Programmer / WebMaster | My schedule is already full." LeTourneau University | -- Henry Kissinger

« previous php.general (#61610) next »