note 37772 added to features.http-auth

From: Date: Wed, 26 Nov 2003 12:30:42 +0000
Subject: note 37772 added to features.http-auth
Groups: php.notes 
Request: Send a blank email to php-notes+get-60997@lists.php.net to get a copy of this message
The logout procedure descripted in the page didn't work at all. Here is a code snippet that we used in our pages to do get the job done (with mysql users db): Most of the code was taken from php.net function authenticate ($realm="Secure Area" ,$errmsg="Please enter a username and password" ) { Header("WWW-Authenticate: Basic realm=\"$realm\""); Header("HTTP/1.0 401 Unauthorized"); die($errmsg); } function db_authenticate($table="mysql.users",$realm="Secure Area" ,$errmsg="Please enter a username and password" ,$user_field="" ,$password_field="" ,$cod_field=-1, $logout ) { if ($logout=="true") { $oldName=$_SERVER['PHP_AUTH_USER']; unset ($_SERVER['PHP_AUTH_PW']); unset ($_SERVER['PHP_AUTH_USER']); session_destroy(); header("Location: http://".$oldName.":YourPassword@<yourURL>/<your auth page>"); die(); } if (empty($_SERVER['PHP_AUTH_USER']) ) { authenticate($realm,$errmsg); } else { if (empty($user_field)) { $user_field = "username"; } if (empty($password_field)) { $password_field = "password"; } $query = "select $cod_field from $table where $password_field = (lower('".$_SERVER['PHP_AUTH_PW']."')) and $user_field = lower('".$_SERVER['PHP_AUTH_USER']."') "; $result = ckQuery($query); if ( (mysql_numrows($result)<=0) ) { authenticate($realm,$errmsg); }else { $users=array(); $users['<account_cod>']=mysql_result($result,0,0); // Personalize the query to retrieve the data $users['<account_username>']=mysql_result($result,0,2); return $users; //this an array filled with the user data } } } CALL EXAMPLE: $lOut=$_GET['logout']; //If true then do the logout if (!isset($lOut)) $lOut="false"; session_register("user"); $user=db_authenticate(<accouts table>,<form name>,<login error string>,<mysql user field>,<mysql password field>,<mysql account key>,$lOut); header("Location: <main page for logged users>"); Hope that this works ---- Manual Page -- http://www.php.net/manual/en/features.http-auth.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37772 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37772&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37772&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#60997) next »