note 47501 deleted from function.session-start by tomsommer
| From: | tomsommer@php.net | Date: | Thu, 18 Nov 2004 19:41:51 +0000 |
| Subject: | note 47501 deleted from function.session-start by tomsommer | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-80718@lists.php.net to get a copy of this message | ||
Note Submitter: codelander at exsisto dot com
----
Guys,
I've been trying to overcome the http auth logout issue and I've finally decided to work
out something on my own.
Please find below WORKING example. I'll be glad if it would be helpfull!
* Sample below expects valid user account to be specified, you could handle user authorization
through DB or any other way. Sample will authorize: validuser1 or validuser2 disregarding the
specified password.
<?php
session_start();
function httpauth()
{
header('WWW-Authenticate: Basic realm="Secure"');
header('HTTP/1.0 401 Unauthorized');
}
if ($_GET["logout"]=="logout")
{
echo "<br>".$PHP_AUTH_USER ." - You have been logged out!";
echo "<br><br><a href=\"index.php\">Login
again?</a>";
$_SESSION['logout']=1;
exit;
}
if ( ($PHP_AUTH_USER == "validuser1") || ($PHP_AUTH_USER == "validuser2"))
{
if ($_SESSION['logout']==1)
{
httpauth();
$_SESSION['logout']=0;
exit;
}
echo "<br>Here!";
echo "<br><br>logged in as: ". $PHP_AUTH_USER;
echo "<br><br><a
href=\"index.php?logout=logout\">Logout</a>";
}
else
{
httpauth();
exit;
}
?>