Re: SSL secure pages

From: Date: Sat, 29 Jul 2000 15:19:46 +0000
Subject: Re: SSL secure pages
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-8960@lists.php.net to get a copy of this message
Jeff Dickey wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Of course, one quick hack that would let a single page flip from > secure to non-secure (or vice versa) would be through the use of the > META HTTP-EQUIV Refresh tag. Right? Not sure what that would accomplish. Sometimes a refresh is a "good thing" - it allows you to controlled redirects, such as "The page has moved. Click here to go there, or wait 15 seconds" However, there is bad too: meta refreshes that have 0 seconds for a delay make it a pain in the #$% to use the "back" button on the browser, since backing up to the refresh page always causes the browser to move forward again to the new page. I would not recommend using it for this scenario. A straightforward scenario is to say "logged-in" access must be secure, non-logged in need not be secure. Then, decide on the page flow for both scenarios. You will find that some pages may be non-secure, some may be secure only, and otherwise may be a "mixture" of both, where the content is dynamically generated based on if the person is logged in or not. Use your own "is_logged_in()" function to control which navigation options you present, and what content goes on to secure pages. Also, you may need to use the "is_logged_in" function even on the non-secure pages, if you need to dynamically control which navigation options you present. Ok...this is getting wordy, but here's a concrete example: Template structure of page splits into a standard "header", a standard "navigation bar" across the top, a "body", and a standard "footer". So, a typical page called "showaccounts.html" might look like <? require 'header.html'; ?> <? require 'navbar.html'; ?> <!-- BEGIN BODY --> if(is_logged_in()) { include 'accountbody.html'; } else { include 'notloggedin.html'; } <!-- END BODY --> <? require 'footer.html'; ?> ==================================== Navbar example (replace "optionx" with appropriate href tags option1 option2 option3 <? if(is_logged_in()) { printf("Option 3\n"); printf("Option 4\n"); printf("Option 5\n"); } ?> ============== The above navbar can be include into any page, and will dynamically adjust itself for content based on if the user is logged in. (and of course, if the user isn't coming over ssl, then he isn't logged in, so non-secure users would always get only 1st 3 options. This is only one example. There are many other ways of doing this. Cheers, Thomas

« previous php.general (#8960) next »