Re: Secure User Auth
| From: | James Arthur | Date: | Sun, 03 Feb 2002 18:28:38 +0000 |
| Subject: | Re: Secure User Auth | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-83319@lists.php.net to get a copy of this message | ||
On Sunday 03 Feb 2002 17:43, Viper wrote:
> Well it depends what you want to do, Do they need to just get into the app
> or do they need to have different access levels? If they dont need access
> levels just use htaccess that should work out fine.
>
htaccess isn't secure enough, since it sends the password in plain text to
the server. Besides, the users already have accounts on the server, so it
would make more sense to authenticate against an existing system, like
IMAP/POP3. Doing that's easy enough, and also has the side effect that when
they log in it tells them whether they have new mail or not.
The problem is finding a way to enter login details that does not send the
password across the internet in plain text mode. The only way seems to use
SSL, but I don't know how to implement it.
--jaa