Problems with Caching, HTTP_AUTH and PHP_AUTH_USER
| From: | Boget, Chris | Date: | Fri, 02 Jun 2000 18:40:35 +0000 |
| Subject: | Problems with Caching, HTTP_AUTH and PHP_AUTH_USER | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-916@lists.php.net to get a copy of this message | ||
Here is my situation:
We use authentication very similar to what is demonstrated
in the manual. We send a 401 header to pop up the login
dialog then we take that information and query a mysql
database to determine if the login is valid.
To get into the site, the user is taken to a file: login.php3.
The only thing in that file is a call to my master login
function that validates the ID/PW information, determines
what type of user it is and directs them to the proper place
(via a header() call). If the information is incorrect, the
function returns and the page then displays an error.
In each page of the password protected section of the site,
I call a different function that just validates the ID/PW and
boots the user out if it is not correct. The problem I'm
experiencing is more with the login.php3 and here it is:
A user will go to that page and put in their ID/PW to log
in. The information is good and so they are allowed in.
They go about their business, finish up and close out the
browser. Now, someone different goes to the site and they
are taken to the login.php3 page. They do not have a
valid ID/PW and so after 3 tries, they are given the afore-
mentioned error message and click the back button to
go back to the previous menu. However, if that user then
clicks the forward button to return and see the error
message, the user is instead presented with the menu for
the user who previosuly logged in. It is as if the browser
caches the previous users authentication information. While
I do not know if this is the case, I do know that it is caching
something because this only happens when the browser is
not set up to check for new versions of a web page every visit.
If the browser is set up to check every time, this problem does
not occur.
Since this is almost certainly a caching issue, I thought I'd
be able to nip the problem in the bud by sending the
following headers right before I send the 401 authentication
header:
header("Pragma: no-cache");
header("Cache-Control: no-cache, must-revalidate");
header("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT");
header("Expires: Mon, 26 Jul 1997 05:00:00 GMT");
However, that did not solve my problem and I'm not sure why.
Has anyone ever experienced something like this? Does any
one have any suggestions?
Here is the relevant code:
login.php3:
<script language="php">
$pageTitle = "Login";
require( "auth_func.php3" );
require( "html_func.php3" );
masterLogin();
HTMLHeader( $pageTitle );
echo "<br>\n";
echo "<p align=\"center\">The User-ID and Password you have provided are
invalid.
<br>\n";
echo "Please double check your information and try again.\n";
echo "<br><br>\n";
echo "<center>
<a href=\"/interactive/main_menu.php3\">Return to the Main
Menu</a>
</center>\n";
HTMLFooter();
</script>
auth_func.php3
function authenticateUser() {
global $realm;
header( "Pragma: no-cache" );
header( "Cache-Control: no-cache, must-revalidate" );
header( "Last-Modified: " . gmdate( "D, d M Y H:i:s" ) . " GMT" );
header( "Expires: Mon, 26 Jul 1993 05:00:00 GMT" );
header( "WWW-authenticate: basic realm=\"$realm\"" );
header( "HTTP/1.0 401 Unauthorized" );
}
function masterLogin() {
global $PHP_AUTH_USER, $PHP_AUTH_PW;
global $validAdmin,
$validBroker,
$validClientBound,
$validClientUnBound,
$validDirectBound,
$validDirectUnBound;
global $dbname;
if( !$PHP_AUTH_USER ) {
authenticateUser();
return 0;
}
/* This connects to the database on the local web server */
mysql_pconnect( );
/* select the user and password combo */
$query = "select * from this_login_table where ";
$query .= "uid = '$PHP_AUTH_USER' and ";
$query .= "pass = '$PHP_AUTH_PW' and ";
$query .= "void <> 1";
$result = mysql( "$dbname", "$query" );
if( !$result ) {
authenticateUser();
return 0;
}
/* If there is one row, they have the right password */
$num = mysql_NumRows( $result );
if( $num==1 ) {
$type = mysql_result($result,0,"field1");
$active = mysql_result($result,0,"field2");
$level = mysql_result($result,0,"field3");
$uid = mysql_result($result,0,"field14");
if( $active==0 ) {
/* This account is not yet active */
authenticateUser();
return 0;
}
// Code that rediects users is here
// I use the header( "location: " ); to redirect
}
}
Any help would be most gratefully appreciated!!
Chris