Re: SSL secure pages
| From: | Thomas Reinke | Date: | Sat, 29 Jul 2000 15:19:46 +0000 |
| Subject: | Re: SSL secure pages | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8960@lists.php.net to get a copy of this message | ||
Jeff Dickey wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Of course, one quick hack that would let a single page flip from
> secure to non-secure (or vice versa) would be through the use of the
> META HTTP-EQUIV Refresh tag. Right?
Not sure what that would accomplish. Sometimes a refresh is a
"good thing" - it allows you to controlled redirects, such as
"The page has moved. Click here to go there, or wait 15 seconds"
However, there is bad too: meta refreshes that have 0 seconds
for a delay make it a pain in the #$% to use the "back" button
on the browser, since backing up to the refresh page always
causes the browser to move forward again to the new page.
I would not recommend using it for this scenario. A
straightforward scenario is to say "logged-in" access
must be secure, non-logged in need not be secure.
Then, decide on the page flow for both scenarios.
You will find that some pages may be non-secure, some
may be secure only, and otherwise may be a "mixture"
of both, where the content is dynamically generated
based on if the person is logged in or not.
Use your own "is_logged_in()" function to control
which navigation options you present, and what content
goes on to secure pages. Also, you may need to use the
"is_logged_in" function even on the non-secure pages,
if you need to dynamically control which navigation
options you present.
Ok...this is getting wordy, but here's a concrete example:
Template structure of page splits into a standard "header",
a standard "navigation bar" across the top, a "body",
and a standard "footer".
So, a typical page called "showaccounts.html"
might look like
<? require 'header.html'; ?>
<? require 'navbar.html'; ?>
<!-- BEGIN BODY -->
if(is_logged_in()) {
include 'accountbody.html';
} else {
include 'notloggedin.html';
}
<!-- END BODY -->
<? require 'footer.html'; ?>
====================================
Navbar example (replace "optionx" with appropriate href tags
option1
option2
option3
<?
if(is_logged_in()) {
printf("Option 3\n");
printf("Option 4\n");
printf("Option 5\n");
}
?>
==============
The above navbar can be include into any page, and will dynamically
adjust
itself for content based on if the user is logged in. (and of course,
if the user isn't coming over ssl, then he isn't logged in, so
non-secure
users would always get only 1st 3 options.
This is only one example. There are many other ways of doing this.
Cheers, Thomas