RE: [PHP4BETA] IISAPI module: do we really need to have a Filter and Extension?

From: Date: Mon, 06 Dec 1999 15:07:16 +0000
Subject: RE: [PHP4BETA] IISAPI module: do we really need to have a Filter and Extension?
Groups: php.version4 
Request: Send a blank email to php-version4+get-7521@lists.php.net to get a copy of this message
On that same page there is an AUTH_TYPE that defines which type of authentication was used by the client. Anything other than basic will have a null password. Would it be worth-while to add a PHP_AUTH_TYPE variable so that our own authentication routines are aware of potential problems resulting from an earlier authentication filter taking precedence? If we implement this, the documentation should have the following warning: Note: In respect to AUTH_TYPE, if the string is not empty it does not mean the user was authenticated (if the authentication scheme is not Basic or integrated Windows authentication). The server allows authentication schemes it does not natively support because an ISAPI filter may be able to handle that particular scheme. This is from Microsoft's MSDN web page. Thanx. Peter -----Original Message----- From: Nuno Leitao [mailto:nuno@zeustechnology.com] Sent: Monday, December 06, 1999 8:01 AM To: Thies C. Arntzen Cc: Zeev Suraski; php4beta@lists.php.net Subject: Re: [PHP4BETA] IISAPI module: do we really need to have a Filterand Extension? Hi ya, "Thies C. Arntzen" wrote: > the zeus-server will give us this information > (MS_REMOTE_USER,MS_REMOTE_PASSWD), so i guess i'll use > it for the zeus-isapi module and we'll keep it as it is for the M$-IIS. I'm sorry -- I looked at the wrong side of the #define :) The variables are actually called: "REMOTE_USER" and "REMOTE_PASSWD", *not* "MS_REMOTE_USER" and "MS_REMOTE_PASSWD". Sorry for that. If you go to: http://msdn.microsoft.com/library/psdk/iisref/isre504l.htm there is a password list. Apparently IIS doesn't define REMOTE_PASSWD, but they define their own "AUTH_USER" and "AUTH_PASSWD" for the same purpose. You should note however that these variables are only available if you are using the "Basic" authentication method. Cheers. -- Nuno Leitao (nleitao@zeustechnology.com) Zeus Technology Limited http://www.zeustechnology.com St. John's Innovation Park, Cowley Road, Cambridge, CB4 4WS, UK tel : +44(0)1223 421814 fax : +44(0)1223 421731 -- PHP 4.0 Beta Mailing List <http://www.php.net/version4/> To unsubscribe, e-mail: php4beta-unsubscribe@lists.php.net For additional commands, e-mail: php4beta-help@lists.php.net To contact the list administrators, e-mail: php4beta-admin@lists.php.net

« previous php.version4 (#7521) next »