Re: NT Authentication
| From: | Phil Driscoll | Date: | Tue, 13 Jun 2000 08:40:41 +0000 |
| Subject: | Re: NT Authentication | ||
| Groups: | php.windows | ||
| Request: | Send a blank email to php-windows+get-427@lists.php.net to get a copy of this message | ||
>All you need is to clear anonymous permission on the web folder
>(if you use IIS or PWS). Can't say anything for apache or other web
servers.
I don't think it's as simple as that (for php running as a CGI at least).
If you clear anonymous permission for a php file, php.exe starts up as the
anonymous user (normally IUSR_YOURSERVERNAME) and then doesn't have
sufficient
permission to open the php file, and reports back an error saying that it
cannot
open the input file. All this happens too late in proceedings for the server
to
send back a request for authentication.
However, if you can get the user who needs to access the protected php page
to
first access a plain html page (not parsed by any cgis) in the same
directory
(or higher) as the php file, then the server will handle authentication for
the
plain page, and then the browser will automatically send the correct
authentication
for subsequent requests to the php file, and hence php.exe will get run as a
user
with sufficient permissions to read the php file.
Cheers
--
Phil Driscoll
Dial Solutions
+44 (0)113 294 5112
http://www.dialsolutions.com
http://www.dtonline.org