note 51399 added to features.http-auth
| From: | lexaattoxadotde at osu1 dot php dot net | Date: | Tue, 29 Mar 2005 20:17:16 +0000 |
| Subject: | note 51399 added to features.http-auth | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-87160@lists.php.net to get a copy of this message | ||
/**
After many tries, I created a login/logout-mechanism, which works
with Internet Explorer (tested on IE6) and Firefox (tested on V1.0).
I've combined some of the hints given below and used a session as
a second independent memory.
check4login() has to be called on every loading of the page.
**/
function check4login() {
$baselink = "http://" . $_SERVER['HTTP_HOST'] .
$_SERVER['PHP_SELF'];
// start a session and don't let it stop automatically:
session_set_cookie_params(0);
session_start();
setcookie("PHPSESSID", session_id());
// check if the current loading of the page is the first loading
// after a logout:
if ($_SESSION['logout'] != '') {
unset($_SESSION['logout']);
//
// initialize a relogin on Firefox
// (request login with username "relogin"):
//
// CAUTION: After that, relative hyperlinks like
// <a href="{$_SERVER['PHP_SELF']}">Link</a>
// will maybe translated into an absolute hyperlink like
// http://relogin:relogin@...
// which will lead to an error-message in Firefox.
//
// So you always have to use absolute hyperlinks like $baselink.
//
if (! preg_match("/MSIE/", $_SERVER['HTTP_USER_AGENT'])) {
$link = preg_replace("/^http:\/\/(.*)$/",
"http://relogin:relogin@$1",
$baselink);
header("Location: $link");
exit;
} }
// check if a new realm needs to be generated because
// it's the first loading of the page (or the first loading
// after a logout):
//
// Remark: The realm is generated with some random signs,
// because Internet Explorer will forget the username if the
// realm changes. Unfortunately Firefox doesn't do so.
if (! isset($_SESSION['realm'])) {
srand();
$_SESSION['realm'] = "My Realm ";
for ($i = 0; $i < 6; $i++) {
$_SESSION['realm'] .= substr(".,:;-_'+~=", rand(0, 9), 1);
} }
// check if a user has already logged in before:
if (isset($_SESSION['user'])) {
unset($_SESSION['login']);
return true;
}
// check if a user just entered a username and password:
//
// is_authorized() has to return 'true' if and only if
// the username and the passwort given are correct.
if (isset($_SESSION['login'])) {
if (is_authorized($_SERVER['PHP_AUTH_USER'],
$_SERVER['PHP_AUTH_PW'])) {
$_SESSION['user'] = $_SERVER['PHP_AUTH_USER'];
unset($_SESSION['login']);
return true;
} }
// let the browser ask for a username and a password:
$_SESSION['login'] = true;
header("WWW-Authenticate: Basic realm=\"{$_SESSION['realm']}\"");
header("HTTP/1.0 401 Unauthorized");
echo "You need to log in before you can access this page.";
phpinfo(); // - for testing only
exit;
}
function logout() {
// to do a logout, all session-variables will be deleted,
// a variable 'logout' is added:
$_SESSION = array('logout' => true);
echo "You were successfully logged out.";
phpinfo(); // - for testing only
exit;
}
----
Manual Page -- http://www.php.net/manual/en/features.http-auth.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+51399
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+51399&report=yes
Search -- http://master.php.net/manage/user-notes.php