Re: HTTP Authentication / Logging Out
| From: | Chris Lee | Date: | Mon, 01 Oct 2001 22:54:55 +0000 |
| Subject: | Re: HTTP Authentication / Logging Out | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-69508@lists.php.net to get a copy of this message | ||
php is serverside, PHP_AUTH_USER is set by the client, therfore when you
unset() the serverside instance of PHP_AUTH_USER the client doesnt know
about this and keeps sending the username/pass. the only way I know of is to
re-send the http auth headers and change the domain. this works for me.
Header("WWW-Authenticate: Basic realm='someother-domain' ");
Header("HTTP/1.0 401 Unauthorized");
--
Chris Lee
lee@mediawaveonline.com
"Eric J Schwinder" <eric.AT.bergencomputing.DOT.com@pb1.pair.com> wrote in
message news:20011001223641.43950.qmail@pb1.pair.com...
> I used a pretty basic system to check HTTP authentication values against
> database values, but I can't seem to find a way to allow the user to log
> out. I tried:
>
> unset($PHP_AUTH_USER)
>
> but Internet Explorer hangs on to that value until all browser windows are
> closed. Is there any way around that?
>
> Thanks,
>
> Eric J Schwinder
> eric.AT.bergencomputing.DOT.com
>
>