Re: PHP based authentification -----------
| From: | Richard Lynch | Date: | Sun, 19 Aug 2001 20:54:39 +0000 |
| Subject: | Re: PHP based authentification ----------- | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-63428@lists.php.net to get a copy of this message | ||
> How can I "logout" from a PHP based auth (with PHP_AUTH_USER and
PHP_AUTH_PW
> and appropriate headers sent at the beginning)?
> It seems like unset($PHP_AUTH_USER) does not wotk in this case...
unset() won't do anything because the *BROWSER* re-sends the
username/password for that Realm when it gets the headers requiring them.
This continues until the user quits the browser, *OR* you stop
authenticating for that Realm and start authenticating for another.
Thus, the way to "logout" is to maintain a dynamic unique dataset of
"Realms" and require authentication in a new Realm for any user that is
"logged out".
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm