note 71069 added to features.http-auth
| From: | Whatabrain at osu1 dot php dot net | Date: | Fri, 10 Nov 2006 15:05:21 +0000 |
| Subject: | note 71069 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-119586@lists.php.net to get a copy of this message | ||
Back to the problem of authenticating in CGI mode... mcbethh suggested using this to set a local
variable in php:
RewriteRule .* - [E=REMOTE_USER:%{HTTP:Authorization},L]
It didn't work. I couldn't see the variable. My solution is pretty round-about, but it
works:
RewriteEngine on
RewriteCond %{HTTP:Authorization} !^$
RewriteCond %{REQUEST_METHOD} =GET
RewriteCond %{QUERY_STRING} =""
RewriteRule ^page.php$ page.php?login=%{HTTP:Authorization}$1
This causes the Auth string to be added to the URL if there are no parameters and it's a GET
request. This prevents POSTs and parameter lists from being corrupted.
Then, in the PHP script, I store the Auth string as a session cookie.
So the only way to log in to my script is to go to the url with no parameters.
----
Server IP: 216.194.113.175
Probable Submitter: 24.147.173.242
----
Manual Page -- http://www.php.net/manual/en/features.http-auth.php
Edit -- https://master.php.net/note/edit/71069
Del: integrated -- https://master.php.net/note/delete/71069/integrated
Del: useless -- https://master.php.net/note/delete/71069/useless
Del: bad code -- https://master.php.net/note/delete/71069/bad+code
Del: spam -- https://master.php.net/note/delete/71069/spam
Del: non-english -- https://master.php.net/note/delete/71069/non-english
Del: in docs -- https://master.php.net/note/delete/71069/in+docs
Del: other reasons-- https://master.php.net/note/delete/71069
Reject -- https://master.php.net/note/reject/71069
Search -- https://master.php.net/manage/user-notes.php