note 20444 rejected from features.http-auth by zak

From: Date: Thu, 04 Apr 2002 08:22:06 +0000
Subject: note 20444 rejected from features.http-auth by zak
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-28592@lists.php.net to get a copy of this message
first my code that needs some fixing (maybe) and commenting and then couple of silly questions... <PRE> function authenticate_user() { Header("WWW-Authenticate: Basic realm=\"Restricted Admin Area\""); Header("HTTP/1.0 401 Unauthorized"); echo "You are not authorized to enter this section of the site!\n"; exit; } if($id==666) { if(!isset($PHP_AUTH_USER)) { authenticate_user(); } else { $pass = $PHP_AUTH_PW; $user = $PHP_AUTH_USER; if($user=="admin" AND $pass=="password") {} else {authenticate_user();} } header ("Cache-Control: no-cache, must-revalidate"); // HTTP/1.1 header ("Pragma: no-cache"); // HTTP/1.0 } </PRE> 1.is this SAFE(crypted or something) to send my username and password this way through this popup-auth-window? 2.much bigger problem... I used to use this kind of authentification earlier on simple pages (on linux servers), but recently runned into a silly situation ... this time server is NT 4.0 and webserver is IIS 4.0 also and php is used through isapi (php4isapi.dll) and everything SEEMED to work as before but I didnt manage to log on never ever with admin and password like before ... always treated me as I were entered wrong password or something... but when I found out the problem I was quite surprised and really mad actually -> the damn authentification thingie compared my entered name and password with NT-s SYSTEM USER DATABASE _FIRST_, and THEN did send them for my code to check for validation... so basically the name and password were checked for validation twice... first by system and second time through my code... so everyone who entered his user name and password for this NT server could get in from first part... well of course I could have used this and then my code could have checked who really can get in ... buuut as you understand I dont want to send my NT server login information there at the first place (for security reasons) and want to use my own unique user database for webpage... so what or how could I get this thing working in NT server normally without NT system check on user?

« previous php.notes (#28592) next »