note 32697 deleted from ref.ldap by betz
| From: | betz@php.net | Date: | Sun, 19 Oct 2003 12:49:30 +0000 |
| Subject: | note 32697 deleted from ref.ldap by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-58886@lists.php.net to get a copy of this message | ||
Note Submitter: kenlbro@earthlink.net
----
If all else fails...Here is a quick, easy, cheat way to "piggy back" your authentication
needs on top of someone else's authentication scheme.
Typically in a large company, there is a web-accessible email application or a company intranet page
that requires authentication. Find it. It doesn't matter if they are using Exchange, LDAP, or
whatever.
In a web browse try to place your username and password in the URL to see if it authenticates you.
For example: http://username:password@intranet.company.com/.
If you gain access without having to login, then you can use that page to do your authentication:
$fp=@fopen("http://username:password@intranet.company.com/","r");
if ($fp) {$userisauthenticated=true; fclose($fp);} else {$userisauthenticated=false;}
I know this is not the right way to go about it, but it works and can often prevent "petty turf
wars". :-)