note 20394 added to function.session-destroy
| From: | msopacua at idg dot nl | Date: | Tue, 02 Apr 2002 14:34:37 +0000 |
| Subject: | note 20394 added to function.session-destroy | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-28502@lists.php.net to get a copy of this message | ||
If you use sessions with HTTP Auth, you might find the code below do what you expect:
session.h.php - should be included in every 'protected' page:
<?php
define("HTTP_AUTH_REALM", "Your authname here");
session_start();
if(!isset($_SESSION["uid"])) {
// No session, let's lookup the user.
if(!isset($_COOKIE['login_attempts']))
{
unset($_SERVER['PHP_AUTH_USER']);
// Gives the user 30 seconds to type the password.
// Should be enough :-)
setcookie('login_attempts', 1,time()+30);
}
if(!isset($_SERVER['PHP_AUTH_USER']))
{
header("WWW-Authenticate: Basic realm=\"".HTTP_AUTH_REALM."\"");
header("HTTP/1.0 401 Unauthorized");
echo("This is for authorized users only.");
exit;
}
// your session registering here
// Please note to verify a password and display a 403 error.
?>
logout.php:
<?php
require('session.h.php');
// Unset session data
$_SESSION=array();
// Clear cookie
unset($_COOKIE[session_name()]);
// Destroy session data
session_destroy();
// Redirect to clear the cookie.
$time=time();
header("Location: /logged_out.html?cache_defeat=$time");
exit;
?>
--
http://www.php.net/manual/en/function.session-destroy.php
http://master.php.net/manage/user-notes.php?action=edit+20394
http://master.php.net/manage/user-notes.php?action=delete+20394
http://master.php.net/manage/user-notes.php?action=reject+20394