note 40958 deleted from features.http-auth by nlopess
| From: | nlopess@php.net | Date: | Thu, 25 Mar 2004 14:13:37 +0000 |
| Subject: | note 40958 deleted from features.http-auth by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-67154@lists.php.net to get a copy of this message | ||
Note Submitter: Steve@n.ext
----
Hi,
I spend long hours to put this all together.
The code you see below, uses a database to gather the UserName and Password.
I will use the function "LoginIsValid" to determine if the login is a valid logon
<?php
// First, establish a connection to the database:
MySQL_Connect("127.0.0.1", "UserName", "Password");
@MySQL_Select_DB("DatabaseName");
// Now, lets login:
if (!LoginIsValid()) {
header('WWW-Authenticate: Basic realm="Staff only"');
header('HTTP/1.0 401 Unauthorized');
echo '<h1>Authorization required!</h1>';
exit;
} else{
$IsLoggedIn=true;
}
// Check the login for validation:
function LoginIsValid(){
// Get the login data:
$GetUSR=$_SERVER['PHP_AUTH_USER'];
$GetPWD=$_SERVER['PHP_AUTH_PW'];
// $GetPWD=md5($GetPWD); // Encrypt
$result=MySQL_Query("SELECT * FROM users");
$num=MySQL_Num_Rows($result);
$i=0;
while($i<$num){
$ThisUSR=MySQL_Result($result,$i,"UserName");
$ThisPWD=MySQL_Result($result,$i,"Password");
if($ThisUSR==$GetUSR && $ThisPWD==$GetPWD){
return true;
}
++$i;
}
}
If ($IsLoggedIn){
/////////////////////////////////
/// Content stuff goes here ///
/////////////////////////////////
}
MySQL_Close(); // Close connection to the MySQL server.
?>
An easier version of all this junk would be without the database thing:
<?php
// ...
function LoginIsValid(){
// Get the login data:
$GetUSR=$_SERVER['PHP_AUTH_USER'];
$GetPWD=$_SERVER['PHP_AUTH_PW'];
if ($GetUSR=="King" && $GetPWD=="sesame"){
return true;
}
}
// ...
?>
Now, it works fine for me now :)
Happy coding!