note 17560 added to features.http-auth

From: Date: Fri, 14 Dec 2001 06:25:42 +0000
Subject: note 17560 added to features.http-auth
Groups: php.notes 
Request: Send a blank email to php-notes+get-22603@lists.php.net to get a copy of this message
I've found a way to ensure logoff without closing the browser. My method uses cookies. Basically, the user clicks on a hyperlink to logoff. The logoff page will load and set the cookie to the value "signoff". When the user goes back to the password protected pages, it will check the cookie for the value "signoff". If the value exist, it will force re-authentication! Works for me =) Use this in every page that needs authentication <? //connect to database require("connect.php"); Header("Cache-Control: no-cache"); Header("Pragma: no-cache"); Header("Expires: Sat, Jan 01 2000 01:01:01 GMT"); function authenticate_user(){ Header("WWW-Authenticate: Basic realm=\"Employer's Profile\""); Header("HTTP/1.0 401 Unauthorized"); echo "<H1>Authorization Required</H1>This server could not verify that you are authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad password), or your browser doesn't understand how to supply the credentials required."; exit; } $signoff=false; if(isset($session_id)){ if($session_id=="signedoff"){ $signoff=true; } } $result = mysql_query("SELECT * FROM Company where c_email='$PHP_AUTH_USER' and c_password='$PHP_AUTH_PW'"); if((!$userExist=mysql_fetch_array($result)) || ($signoff)){ /** change the value of the cookie, so $signoff=false and it won't re-authenticate, you can set the cookie session_id to whatever value you want, as long as its value is not "signoff" */ mt_srand ((double) microtime() * 1000000); $sessionVar=md5(mt_rand()); // reset cookie setcookie("session_id","$sessionVar",0); authenticate_user(); } ?> Use this for the logoff page. User will be "logged off" when this page loads. <? require("connect.php"); /** reset $session_id, the 0 parameter will retain the value until the browser is closed. This is what we need =) */ setcookie("session_id","signedoff",0); ?> -- http://www.php.net/manual/en/features.http-auth.php http://master.php.net/manage/user-notes.php?action=edit+17560 http://master.php.net/manage/user-notes.php?action=delete+17560 http://master.php.net/manage/user-notes.php?action=reject+17560

« previous php.notes (#22603) next »