note 17560 added to features.http-auth
| From: | sputnikdog at yahoo dot com | Date: | Fri, 14 Dec 2001 06:25:42 +0000 |
| Subject: | note 17560 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-22603@lists.php.net to get a copy of this message | ||
I've found a way to ensure logoff without closing the browser. My method uses cookies.
Basically, the user clicks on a hyperlink to logoff. The logoff page will load and set the cookie to
the value "signoff".
When the user goes back to the password protected pages, it will check the cookie for the value
"signoff". If the value exist, it will force re-authentication! Works for me =)
Use this in every page that needs authentication
<?
//connect to database
require("connect.php");
Header("Cache-Control: no-cache");
Header("Pragma: no-cache");
Header("Expires: Sat, Jan 01 2000 01:01:01 GMT");
function authenticate_user(){
Header("WWW-Authenticate: Basic realm=\"Employer's Profile\"");
Header("HTTP/1.0 401 Unauthorized");
echo "<H1>Authorization Required</H1>This server could not verify that you are
authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad
password), or your browser doesn't understand how to supply the credentials required.";
exit;
}
$signoff=false;
if(isset($session_id)){
if($session_id=="signedoff"){
$signoff=true;
}
}
$result = mysql_query("SELECT * FROM Company where c_email='$PHP_AUTH_USER' and
c_password='$PHP_AUTH_PW'");
if((!$userExist=mysql_fetch_array($result)) || ($signoff)){
/**
change the value of the cookie, so $signoff=false and it won't re-authenticate, you can set the
cookie session_id to whatever value you want, as long as its value is not "signoff"
*/
mt_srand ((double) microtime() * 1000000);
$sessionVar=md5(mt_rand());
// reset cookie
setcookie("session_id","$sessionVar",0);
authenticate_user();
}
?>
Use this for the logoff page. User will be "logged off" when this page loads.
<?
require("connect.php");
/**
reset $session_id, the 0 parameter will retain the value until the browser is closed. This is what
we need =)
*/
setcookie("session_id","signedoff",0);
?>
--
http://www.php.net/manual/en/features.http-auth.php
http://master.php.net/manage/user-notes.php?action=edit+17560
http://master.php.net/manage/user-notes.php?action=delete+17560
http://master.php.net/manage/user-notes.php?action=reject+17560