Re: SSL secure pages

From: Date: Fri, 28 Jul 2000 21:50:47 +0000
Subject: Re: SSL secure pages
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-8871@lists.php.net to get a copy of this message
> > Please note, in order for a form to be submitted securely, the form itself > needs to be generated by and submitted to an > "https://" URL. You can NOT > have the form generated normally and then submit it to an > "https://, since > that is NOT secure. Actually, while not recommended, it is still secure to have an http:// based form submit data to an https:// based URL. The problem with the scenario is that the user doesn't know before hand that the transmission will be secure. But then, if you consider (barring browser warnings which many people disable/ignore), having the form itself be delivered from an https:// based URL does not guarantee anything either- the writer could have been foolish and submit it to an http:// based URL. The only way you can be COMPLETELY assured that your stuff is secure is to have the appropriate browser warnings turned on, and to check the HTML source (which of course we know won't happen). Further to the original question, if(user_is_logged_in() || page_requires_log_in()) issue_page_using_SSL(); We do exactly this sort of thing. We have pages that will present one bit of data if the user is already logged in, and a slightly different version of the same page if the user is NOT logged in. Our logic is something like this: if (user_is_logged_in()) { include 'member_page.html'; } else { include 'hey_you...login.html'; } In some cases, a login prompt is displayed, in others, it is a modified version of the original page. If you are using sessions, then you just need to ensure in the user_is_logged_in() function that you are checking for a valid user. Thomas -- ------------------------------------------------------------ Thomas Reinke Tel: (905) 331-2260 Director of Technology Fax: (905) 331-2504 E-Soft Inc. http://www.e-softinc.com Publishers of SecuritySpace http://www.securityspace.com

« previous php.general (#8871) next »