note 74642 deleted from features.http-auth by bjori
| From: | bjori@php.net | Date: | Sat, 21 Apr 2007 08:07:05 +0000 |
| Subject: | note 74642 deleted from features.http-auth by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-125737@lists.php.net to get a copy of this message | ||
Note Submitter:
Reason: in docs
----
I've a separate login file and use sessions to relogin the users. It works great!
When users browse to the login file after 60 seconds and they are no more logged in, they must
authenticate themselves again:
<?php
session_start();
$password = '6367c48dd193d56ea7b0baad25b19455e529f5ee'; //sha1-crypted: abc123
if($_SESSION['loggedin']) {
//User already logged in
header("location: ./index.php");
exit;
}
if( !isset($_SERVER['PHP_AUTH_USER']) || $_SESSION['timestamp'] < time() - 60
) {
$_SESSION['timestamp'] = time();
Header("WWW-Authenticate: Basic realm=\"Admin panel\"");
Header("HTTP/1.0 401 Unauthorized");
echo "Access denied!";
exit;
}
//Set logged in
$_SESSION['loggedin'] = true;
header("location: ./index.php");
exit;
?>