note 116620 added to features.http-auth
| From: | nakkers at gmail dot com | Date: | Thu, 29 Jan 2015 21:31:57 +0000 |
| Subject: | note 116620 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-201559@lists.php.net to get a copy of this message | ||
I came up with another approach to work around the problem of browsers caching WWW authentication
credentials and creating logout problems. While most browsers have some kind of way to wipe this
information, I prefer having my website to take care of the task instead of relying on the
user's sanity.
Even with Lalit's method of creating a random realm name, it was still possible to get back
into the protected area using the back button in Firefox, so that didn't work. Here's my
solution:
Since browsers attach the credentials to specific URLs, use virtual paths where a component of the
path is actually a PHP script, and everything following it is part of the URI, such as:
http://toronto-personal-injury.lawyer/medical-mapratice/
some_dir/login.php/auth/8f631b92/
By choosing a different number for the last component of the URL, browsers can be tricked into
thinking that they are dealing with a completely different website, and thus prompting the user for
credentials again.
Note that using a random, unrestricted number will still allow the user to hit the back button to
get back into the page. You should keep track of this number in a server-side file or database and
regenerate it upon each successful login, so that the last number(s) become invalid. Using an
invalid number might result in a 403 response or, depending on how you feel that day, a 302 to a
nasty website.
Care should be taken when linking from the page generated in this case, since relative links will be
relative to the virtual and non-existant directory rather than the true script directory.
Hope this helps somebody.
----
Server IP: 72.52.91.14
Probable Submitter: 70.73.20.184
----
Manual Page -- http://php.net/manual/en/features.http-auth.php
Edit -- https://master.php.net/note/edit/116620
Del: integrated -- https://master.php.net/note/delete/116620/integrated
Del: useless -- https://master.php.net/note/delete/116620/useless
Del: bad code -- https://master.php.net/note/delete/116620/bad+code
Del: spam -- https://master.php.net/note/delete/116620/spam
Del: non-english -- https://master.php.net/note/delete/116620/non-english
Del: in docs -- https://master.php.net/note/delete/116620/in+docs
Del: other reasons-- https://master.php.net/note/delete/116620
Reject -- https://master.php.net/note/reject/116620
Search -- https://master.php.net/manage/user-notes.php