note 20444 added to features.http-auth
| From: | priit at ww dot ee | Date: | Wed, 03 Apr 2002 21:47:35 +0000 |
| Subject: | note 20444 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-28573@lists.php.net to get a copy of this message | ||
first my code that needs some fixing (maybe) and commenting and then couple of silly questions...
<PRE>
function authenticate_user()
{
Header("WWW-Authenticate: Basic realm=\"Restricted Admin Area\"");
Header("HTTP/1.0 401 Unauthorized");
echo "You are not authorized to enter this section of the site!\n";
exit;
}
if($id==666)
{
if(!isset($PHP_AUTH_USER))
{
authenticate_user();
} else {
$pass = $PHP_AUTH_PW;
$user = $PHP_AUTH_USER;
if($user=="admin" AND $pass=="password") {} else {authenticate_user();}
}
header ("Cache-Control: no-cache, must-revalidate"); // HTTP/1.1
header ("Pragma: no-cache"); // HTTP/1.0
}
</PRE>
1.is this SAFE(crypted or something) to send my username and password this way through this
popup-auth-window?
2.much bigger problem... I used to use this kind of authentification earlier on simple pages (on
linux servers), but recently runned into a silly situation ... this time server is NT 4.0 and
webserver is IIS 4.0 also and php is used through isapi (php4isapi.dll) and everything SEEMED to
work as before but I didnt manage to log on never ever with admin and password like before ...
always treated me as I were entered wrong password or something... but when I found out the problem
I was quite surprised and really mad actually -> the damn authentification thingie compared my
entered name and password with NT-s SYSTEM USER DATABASE _FIRST_, and THEN did send them for my code
to check for validation... so basically the name and password were checked for validation twice...
first by system and second time through my code... so everyone who entered his user name and
password for this NT server could get in from first part... well of course I could have used this
and then my code could have checked who really can get in ... buuut as you understand I dont want to
send my NT server login information there at the first place (for security reasons) and want to use
my own unique user database for webpage...
so what or how could I get this thing working in NT server normally without NT system check on user?
--
http://www.php.net/manual/en/features.http-auth.php
http://master.php.net/manage/user-notes.php?action=edit+20444
http://master.php.net/manage/user-notes.php?action=delete+20444
http://master.php.net/manage/user-notes.php?action=reject+20444