Re: SSL secure pages
| From: | Thomas Reinke | Date: | Fri, 28 Jul 2000 21:50:47 +0000 |
| Subject: | Re: SSL secure pages | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8871@lists.php.net to get a copy of this message | ||
>
> Please note, in order for a form to be submitted securely, the form itself
> needs to be generated by and submitted to an
> "https://" URL. You can NOT
> have the form generated normally and then submit it to an
> "https://, since
> that is NOT secure.
Actually, while not recommended, it is still secure to have an http://
based form submit data to an https:// based URL. The problem with
the scenario is that the user doesn't know before hand that the
transmission will be secure.
But then, if you consider (barring browser warnings which many
people disable/ignore), having the form itself be delivered
from an https:// based URL does not guarantee anything either-
the writer could have been foolish and submit it to an http://
based URL. The only way you can be COMPLETELY assured that
your stuff is secure is to have the appropriate browser
warnings turned on, and to check the HTML source (which of
course we know won't happen).
Further to the original question,
if(user_is_logged_in() || page_requires_log_in())
issue_page_using_SSL();
We do exactly this sort of thing. We have pages that will
present one bit of data if the user is already logged in,
and a slightly different version of the same page if the
user is NOT logged in.
Our logic is something like this:
if (user_is_logged_in()) {
include 'member_page.html';
} else {
include 'hey_you...login.html';
}
In some cases, a login prompt is displayed, in others, it is
a modified version of the original page. If you are using
sessions, then you just need to ensure in the user_is_logged_in()
function that you are checking for a valid user.
Thomas
--
------------------------------------------------------------
Thomas Reinke Tel: (905) 331-2260
Director of Technology Fax: (905) 331-2504
E-Soft Inc. http://www.e-softinc.com
Publishers of SecuritySpace http://www.securityspace.com