Re: Re: authentication

From: Date: Mon, 27 Aug 2001 18:27:45 +0000
Subject: Re: Re: authentication
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-64673@lists.php.net to get a copy of this message
It seems like there would be several problems with doing it this way. The most obvious is what happens when someone types in http://www.yoursite.com/protected.php?allowed=true In addition to that, how can you tell who is viewing the page? With this setup everyone passes an identical set of info to the server. I would suggest, instead, passing their username and some sort of simple session id ( could be as simple as md5(time()); ) variable and comparing these against stored values in a DB. I have examples of this here: Main Script - http://www.zend.com/codex.php?id=393&single=1 Header File - http://www.zend.com/codex.php?id=397&single=1 Sheridan Saint-Michel Website Administrator FoxJet, an ITW Company www.foxjet.com ----- Original Message ----- From: "Gert Mellak" <gert.mellak@utanet.at> To: <php-general@lists.php.net> Sent: Monday, August 27, 2001 1:06 PM Subject: [PHP] Re: authentication > hi! > > I ever solve this problem with sessions... when a user does the login, I > have > > session_start(); > session_register("allowed"); > $allowed = true; > > and on the top of all the other sites, where just "special" users are > allowed to go in, there is a > > include ("checkAllowed.php"); > > checkAllowed.php just contains: > if (!$allowed) > die ("Access denied"); > > I hope I could help you... if so - or if you have got questions, please feel > free to email me! > > yours, > > gert mellak > ================== > eMail: gert@mellak.com > http://www.mellak.com > > > > > Wilbert Enserink <wilbert@pdd.nl> schrieb in im Newsbeitrag: > 006601c12ef5$aff7c380$0301a8c0@168.1.1... > Hi all, > > > Can anybody help me with this authentication problem? > > Clients can log in using a html form on my site. When they log in their > username and password are checked in a mysql database. Then they are > forwarded to a url, a directory on my site also coming from the db. This > directory should not be public of couse, so I did a chmod 744 on the clients > directory. > > Anybody has any ideas? I prefer not to use the standard window popup thing > for authentication. > I checked the php manual, but there is not much info on plain html forms on > the subject, or maybe it is my English...:-) > > > > Regards, Wilbert > > ------------------------- > Pas de Deux > Van Mierisstraat 25 > 2526 NM Den Haag > tel 070 4450855 > fax 070 4450852 > http://www.pdd.nl > info@pdd.nl > ------------------------- > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#64673) next »