note 51399 added to features.http-auth

From: Date: Tue, 29 Mar 2005 20:17:16 +0000
Subject: note 51399 added to features.http-auth
Groups: php.notes 
Request: Send a blank email to php-notes+get-87160@lists.php.net to get a copy of this message
/** After many tries, I created a login/logout-mechanism, which works with Internet Explorer (tested on IE6) and Firefox (tested on V1.0). I've combined some of the hints given below and used a session as a second independent memory. check4login() has to be called on every loading of the page. **/ function check4login() { $baselink = "http://" . $_SERVER['HTTP_HOST'] . $_SERVER['PHP_SELF']; // start a session and don't let it stop automatically: session_set_cookie_params(0); session_start(); setcookie("PHPSESSID", session_id()); // check if the current loading of the page is the first loading // after a logout: if ($_SESSION['logout'] != '') { unset($_SESSION['logout']); // // initialize a relogin on Firefox // (request login with username "relogin"): // // CAUTION: After that, relative hyperlinks like // <a href="{$_SERVER['PHP_SELF']}">Link</a> // will maybe translated into an absolute hyperlink like // http://relogin:relogin@... // which will lead to an error-message in Firefox. // // So you always have to use absolute hyperlinks like $baselink. // if (! preg_match("/MSIE/", $_SERVER['HTTP_USER_AGENT'])) { $link = preg_replace("/^http:\/\/(.*)$/", "http://relogin:relogin@$1", $baselink); header("Location: $link"); exit; } } // check if a new realm needs to be generated because // it's the first loading of the page (or the first loading // after a logout): // // Remark: The realm is generated with some random signs, // because Internet Explorer will forget the username if the // realm changes. Unfortunately Firefox doesn't do so. if (! isset($_SESSION['realm'])) { srand(); $_SESSION['realm'] = "My Realm "; for ($i = 0; $i < 6; $i++) { $_SESSION['realm'] .= substr(".,:;-_'+~=", rand(0, 9), 1); } } // check if a user has already logged in before: if (isset($_SESSION['user'])) { unset($_SESSION['login']); return true; } // check if a user just entered a username and password: // // is_authorized() has to return 'true' if and only if // the username and the passwort given are correct. if (isset($_SESSION['login'])) { if (is_authorized($_SERVER['PHP_AUTH_USER'], $_SERVER['PHP_AUTH_PW'])) { $_SESSION['user'] = $_SERVER['PHP_AUTH_USER']; unset($_SESSION['login']); return true; } } // let the browser ask for a username and a password: $_SESSION['login'] = true; header("WWW-Authenticate: Basic realm=\"{$_SESSION['realm']}\""); header("HTTP/1.0 401 Unauthorized"); echo "You need to log in before you can access this page."; phpinfo(); // - for testing only exit; } function logout() { // to do a logout, all session-variables will be deleted, // a variable 'logout' is added: $_SESSION = array('logout' => true); echo "You were successfully logged out."; phpinfo(); // - for testing only exit; } ---- Manual Page -- http://www.php.net/manual/en/features.http-auth.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+51399 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+51399&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+51399&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#87160) next »