note 31977 added to features.http-auth
| From: | h1suzuki at hotmail dot com | Date: | Sun, 11 May 2003 17:27:46 +0000 |
| Subject: | note 31977 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-47842@lists.php.net to get a copy of this message | ||
my solution to use SSL for password encryption, because the password is sent to web server as plain
text.
insert the following code snipet into the top of secure page.
if (!isset($_SERVER['HTTPS'] || $_SERVER['HTTPS']!="on") {
header("Location: https://$_SERVER['SERVER_NAME']".
$_SERVER['REQUEST_URI']);
exit;
}
if (!isset($_SERVER['PHP_AUTH_USER'] || authenticate()) {
header('WWW-Authenticate: Basic realm="secure"');
header('HTTP/1.0 401 Unauthorized');
echo 'Authorization Required.';
exit;
}
first, redirect to the same URI but SSL-enabled page. then, do authentication.
--
http://www.php.net/manual/en/features.http-auth.php
http://master.php.net/manage/user-notes.php?action=edit+31977
http://master.php.net/manage/user-notes.php?action=delete+31977
http://master.php.net/manage/user-notes.php?action=reject+31977