note 67146 added to features.http-auth
| From: | Louis at osu1 dot php dot net | Date: | Sat, 03 Jun 2006 22:51:08 +0000 |
| Subject: | note 67146 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-113165@lists.php.net to get a copy of this message | ||
I couldn't get authentication to work properly with any of the examples. Finally, I started
from ZEND's tutorial example at:
http://www.zend.com/zend/tut/authentication.php?article=authentication
(validate using .htpasswd) and tried to deal with the additional cases. My general conclusion is
that changing the realm is the only reliable way to cause the browser to ask again, and I like to
thank the person who put that example in the manual, as it got me on the right path. No matter what,
the browser refuses to discard the values that it already has in mind otherwise. The problem with
changing the realm, of course, is that you don't want to do it within a given session, else it
causes a new request for a password. So, here goes, hopefully the spacing isn't too messed up
by the cut'n'paste.
I spent the better part of a day getting this to work right. I had a very hard time thinking through
what the browser does when it encounters an authentication request: seems to me that it tries to get
the password, then reloads the page... so the HTML doesn't get run. At least, this was the case
with IE, I haven't tested it with anything else.
<?php
session_start() ;
if (!isset($_SESSION['realm'])) {
$_SESSION['realm'] = mt_rand( 1, 1000000000 ).
" SECOND level: Enter your !!!COMPANY!!! password.";
header( "WWW-Authenticate: Basic realm=".$_SESSION['realm'] );
// Below here runs HTML-wise only if there isn't a $_SESSION,
// and the browser *can't* set $PHP_AUTH_USER... normally
// the browser, having gotten the auth info, runs the page
// again without getting here.
// What I'm basically getting to is that the way to get
// here is to escape past the login screen. I tried
// putting a session_destroy() here originally, but the
// problem is that the PHP runs regardless, so the
// REFRESH seems like the best way to deal with it.
echo "<meta http-equiv=\"REFRESH\"
content=\"0;url=index.php\">" ;
exit;
}
if ($_POST['logout'] == "logout") {
session_destroy() ;
header('Location: comeagain.php');
exit ;
}
// "standard" authentication code here, from the ZEND tutorial above.
comeagain.php is as follows:
<?
session_start();
unset($_SESSION['realm']);
session_destroy();
echo "<html><head><title>Logged Out</title><h1>Logout
Page</h1><body>" ;
echo "You have successfully logged out of TOGEN";
echo " at ".date("h:m:s")." on ".date("d F Y") ;
echo "<p><a href=\"index.php\">Login Again</a>" ;
echo "</body></html>" ;
?>
The idea is to be able to trash the session (and thus reset the realm) without prompting the browser
to ask again... because it has been redirected to logout.php.
With this combination, I get things to work. Just make sure not to have apache run htpasswd
authentication at the same time, then things get really weird :-).
----
Server IP: 66.163.161.117
Probable Submitter: 65.95.200.171
----
X-Spam-Status: No, hits=4.0 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER,
HTML_MESSAGE,HTML_TAG_BALANCE_HTML autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/features.http-auth.php
Edit -- http://master.php.net/note/edit/67146
Del: integrated -- http://master.php.net/note/delete/67146/integrated
Del: useless -- http://master.php.net/note/delete/67146/useless
Del: bad code -- http://master.php.net/note/delete/67146/bad+code
Del: spam -- http://master.php.net/note/delete/67146/spam
Del: non-english -- http://master.php.net/note/delete/67146/non-english
Del: in docs -- http://master.php.net/note/delete/67146/in+docs
Del: other reasons-- http://master.php.net/note/delete/67146
Reject -- http://master.php.net/note/reject/67146
Search -- http://master.php.net/manage/user-notes.php