note 31977 deleted from features.http-auth by sean
| From: | sean@php.net | Date: | Sun, 21 Nov 2004 15:06:29 +0000 |
| Subject: | note 31977 deleted from features.http-auth by sean | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-80833@lists.php.net to get a copy of this message | ||
Note Submitter: h1suzuki at hotmail dot com
----
my solution to use SSL for password encryption, because the password is sent to web server as plain
text.
insert the following code snipet into the top of secure page.
<?php
if (!isset($_SERVER['HTTPS'] || $_SERVER['HTTPS']!="on") {
header("Location: https://$_SERVER[SERVER_NAME]".
$_SERVER['REQUEST_URI']);
exit;
}
if (!isset($_SERVER['PHP_AUTH_USER'] || authenticate()) {
header('WWW-Authenticate: Basic realm="secure"');
header('HTTP/1.0 401 Unauthorized');
echo 'Authorization Required.';
exit;
}
?>
first, redirect to the same URI but SSL-enabled page. then, do authentication.