Re: HTTP Authentication

From: Date: Thu, 16 Aug 2001 02:08:05 +0000
Subject: Re: HTTP Authentication
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-62949@lists.php.net to get a copy of this message
> I am using PHP to send a header to the browser requestiing authentication. > On a successful login i am tracking inactivity by the client and want to > expire the login once a timeout period is reached. Problem is if the session > expires and the user just refreshes then the orignal login details are > passed to the script. How do I get the client to forget the previous login > details? You can't. It's just not part of the HTTP spec, and you'd have to convince Microsoft, Netscape, Opera, etc to implement. I believe you can use a different REALM after the the user is expired, and then the username/password presented will not be valid. This requires that you have a scheme for tracking various REALMs to present to browser in your HTTP Authentication, so you never re-present the same one twice to any given user. Getting this right can be a bit tricky, but it's been done, and it's been posted at least once, so it's in the archives... -- WARNING richard@zend.com address is an endangered species -- Use ceo@l-i-e.com Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm Volunteer a little time: http://chatmusic.com/volunteer.htm

« previous php.general (#62949) next »