Re: HTTP Authentication
| From: | Richard Lynch | Date: | Thu, 16 Aug 2001 02:08:05 +0000 |
| Subject: | Re: HTTP Authentication | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-62949@lists.php.net to get a copy of this message | ||
> I am using PHP to send a header to the browser requestiing authentication.
> On a successful login i am tracking inactivity by the client and want to
> expire the login once a timeout period is reached. Problem is if the
session
> expires and the user just refreshes then the orignal login details are
> passed to the script. How do I get the client to forget the previous login
> details?
You can't. It's just not part of the HTTP spec, and you'd have to convince
Microsoft, Netscape, Opera, etc to implement.
I believe you can use a different REALM after the the user is expired, and
then the username/password presented will not be valid.
This requires that you have a scheme for tracking various REALMs to present
to browser in your HTTP Authentication, so you never re-present the same one
twice to any given user.
Getting this right can be a bit tricky, but it's been done, and it's been
posted at least once, so it's in the archives...
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm