note 20394 added to function.session-destroy

From: Date: Tue, 02 Apr 2002 14:34:37 +0000
Subject: note 20394 added to function.session-destroy
Groups: php.notes 
Request: Send a blank email to php-notes+get-28502@lists.php.net to get a copy of this message
If you use sessions with HTTP Auth, you might find the code below do what you expect: session.h.php - should be included in every 'protected' page: <?php define("HTTP_AUTH_REALM", "Your authname here"); session_start(); if(!isset($_SESSION["uid"])) { // No session, let's lookup the user. if(!isset($_COOKIE['login_attempts'])) { unset($_SERVER['PHP_AUTH_USER']); // Gives the user 30 seconds to type the password. // Should be enough :-) setcookie('login_attempts', 1,time()+30); } if(!isset($_SERVER['PHP_AUTH_USER'])) { header("WWW-Authenticate: Basic realm=\"".HTTP_AUTH_REALM."\""); header("HTTP/1.0 401 Unauthorized"); echo("This is for authorized users only."); exit; } // your session registering here // Please note to verify a password and display a 403 error. ?> logout.php: <?php require('session.h.php'); // Unset session data $_SESSION=array(); // Clear cookie unset($_COOKIE[session_name()]); // Destroy session data session_destroy(); // Redirect to clear the cookie. $time=time(); header("Location: /logged_out.html?cache_defeat=$time"); exit; ?> -- http://www.php.net/manual/en/function.session-destroy.php http://master.php.net/manage/user-notes.php?action=edit+20394 http://master.php.net/manage/user-notes.php?action=delete+20394 http://master.php.net/manage/user-notes.php?action=reject+20394

« previous php.notes (#28502) next »