Re: Re: authentication
| From: | Sheridan Saint-Michel | Date: | Mon, 27 Aug 2001 18:27:45 +0000 |
| Subject: | Re: Re: authentication | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-64673@lists.php.net to get a copy of this message | ||
It seems like there would be several problems with doing it this way.
The most obvious is what happens when someone types in
http://www.yoursite.com/protected.php?allowed=true
In addition to that, how can you tell who is viewing the page?
With this setup everyone passes an identical set of info to the server.
I would suggest, instead, passing their username and some sort of
simple session id ( could be as simple as md5(time()); ) variable and
comparing these against stored values in a DB.
I have examples of this here:
Main Script - http://www.zend.com/codex.php?id=393&single=1
Header File - http://www.zend.com/codex.php?id=397&single=1
Sheridan Saint-Michel
Website Administrator
FoxJet, an ITW Company
www.foxjet.com
----- Original Message -----
From: "Gert Mellak" <gert.mellak@utanet.at>
To: <php-general@lists.php.net>
Sent: Monday, August 27, 2001 1:06 PM
Subject: [PHP] Re: authentication
> hi!
>
> I ever solve this problem with sessions... when a user does the login, I
> have
>
> session_start();
> session_register("allowed");
> $allowed = true;
>
> and on the top of all the other sites, where just "special" users are
> allowed to go in, there is a
>
> include ("checkAllowed.php");
>
> checkAllowed.php just contains:
> if (!$allowed)
> die ("Access denied");
>
> I hope I could help you... if so - or if you have got questions, please
feel
> free to email me!
>
> yours,
>
> gert mellak
> ==================
> eMail: gert@mellak.com
> http://www.mellak.com
>
>
>
>
> Wilbert Enserink <wilbert@pdd.nl> schrieb in im Newsbeitrag:
> 006601c12ef5$aff7c380$0301a8c0@168.1.1...
> Hi all,
>
>
> Can anybody help me with this authentication problem?
>
> Clients can log in using a html form on my site. When they log in their
> username and password are checked in a mysql database. Then they are
> forwarded to a url, a directory on my site also coming from the db. This
> directory should not be public of couse, so I did a chmod 744 on the
clients
> directory.
>
> Anybody has any ideas? I prefer not to use the standard window popup thing
> for authentication.
> I checked the php manual, but there is not much info on plain html forms
on
> the subject, or maybe it is my English...:-)
>
>
>
> Regards, Wilbert
>
> -------------------------
> Pas de Deux
> Van Mierisstraat 25
> 2526 NM Den Haag
> tel 070 4450855
> fax 070 4450852
> http://www.pdd.nl
> info@pdd.nl
> -------------------------
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net