Re: Sugestions for auth
| From: | Yavor Shahpasov | Date: | Tue, 05 Nov 2002 17:01:48 +0000 |
| Subject: | Re: Sugestions for auth | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-10481@lists.php.net to get a copy of this message | ||
I have two questions i put them here because I doubt most people will read
my whole email :)
a) I think auth should die() after calling the login form, I mean if the
login is displayed then you probably don't want people to see that part of
the page right
b) Is there a way of disabling the message on the built in login form, I
find it good enough for my purposes, and most times I don't need to change
it.
Here is the patch, i hope it is ok I did
#diff -u Auth.php.orig Auth.php > Auth.php.patch
let me know if the patch is not in the right format!
adds three functions
setRequiredUrl - initializes the required urls (accepts string or array)
addRequiredUrl - appends urls to the required urls (same as above)
checkRequiredUrl - checks if $_SERVER['PHP_SELF'] is in the list of urls and
returns true if it is find, using stristr does a case insensiteve search, in
this way if you add /admin/ everything under /admin/ would be protected. It
is called in Auth::start(), it also sets Auth::showLogin to true if it is
found.
calls checkRequiredUrl in the Auth::start
here is a small example (Tried it with Auth and Auth_HTTP)
<?php
ob_start();
include('Auth_HTTP/Auth_HTTP.php');
include('DB.php');
PEAR::setErrorHandling(PEAR_ERROR_PRINT);
$authobj = new Auth_HTTP('DB', $dsn, false, false);
$authobj->addRequiredUrl('/admin/');
$authobj->addRequiredUrl('/file.php');
$authobj->start();
?>
----- Original Message -----
From: "Martin Jansen" <mj@php.net>
To: "Yavor Shahpasov" <yavo@nicosia.com.cy>
Cc: "Wolfram Kriesing" <lists@kriesing.de>; <pear-dev@lists.php.net>
Sent: Monday, November 04, 2002 10:46 PM
Subject: Re: [PEAR-DEV] Sugestions for auth
> On Mon Nov 04, 2002 at 09:5658AM +0200, Yavor Shahpasov wrote:
> > Does this mean I should not bother to implement it and use his auth
instead
> > or should I make the patch
>
> You should definitively provide a patch.
>
> --
> - Martin Martin Jansen
> http://martinjansen.com/
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>