Skip to main content

PHP Authentication

When addressing the need to authenticate a web page (and subsequent pages/resources), integrating user
authentication directly into the design of the web application logic is both convenient (in the sense that
additional layers of communication is unnecessary) and flexible (in the sense that it is easier to integrate
into other applications/scripts when contained in one location). PHP allows three types of authentication:
Hard-coded, file-based and database authentication.

Authentication Variables

Within PHP, there are two pre-defined variables that are used in the authentication of users:
• $_SERVER['PHP_AUTH_USER'] - This variable holds the username that is needed for
authentication.
• $_SERVER['PHP_AUTH_PW'] - This variable holds the password that is needed for
authentication.

Limitations of Authentication Variables

When using the predefined authentication variables, it is important to keep in mind the following
limitations:

• Both variables must be verified at the start of every page. This limitation can be overcome by
having each restricted page wrapped in authentication code (in a separate file) using the REQUIRE()
function.

• The functions do not work properly with the CGI version of PHP - When running PHP through a
web server, there are two distinct options: running it using PHP's CGI SAPI, or running it as a module
for the web server. The CGI version has the advantage of having the php.ini read every time a PHP
page is called up; thus allowing changes in the php.ini to take place immediately (not requiring a
restart of the web server). However, the fact that every time a PHP file is read, the php.ini has to be
read, set its settings and load all of its extensions prior to actually reading the script makes this choice
an unreasonable choice for production environments (may be appropriate in development because
changes made can be seen immediately).

• These functions do not work on Microsoft's IIS server - the username and password are assigned
to the $_SERVER['HTTP_AUTHENTICATION'] variable and must be parsed to obtain the separate
username and password

Comments

Popular posts from this blog

PHP INTRODUCTION

                     PHP  (recursive acronym for  PHP: Hypertext Preprocessor ) is a widely-used open source general-purpose scripting language that is especially suited for web development and can be embedded into HTML. PHP stands for  P HP:  H ypertext  P reprocessor PHP is a server-side scripting language, like ASP PHP scripts are executed on the server PHP supports many databases (MySQL, Informix, Oracle, Sybase, Solid, PostgreSQL, Generic ODBC, etc.) PHP is an open source software PHP is free to download and use Why PHP? PHP runs on different platforms (Windows, Linux, Unix, etc.) PHP is compatible with almost all servers used today (Apache, IIS, etc.) PHP is FREE to download from the official PHP resource:  www.php.net PHP is easy to learn and runs efficiently on the server side What can PHP do? Anything. PHP is mainly focused on server-side scripting, so you can...

MySQL General Architecture

        MySQL operates in a networked environment using a client/server architecture. In other words, a central  program acts as a server, and various client programs connect to the server to make requests. A MySQL  installation has the following major components: MySQL Server, Client programs and MySQL non client  utilities.  MySQL Server MySQL Server, or mysqld, is the database server program. The server manages access to the actual  database (schema) on disk and in memory. MySQL Server is multi-threaded and supports many  simultaneous client connections. Clients can connect via several connection protocols. For managing  database contents, the MySQL server features a modular architecture that supports multiple storage engines  that handle different types of tables (for example, it supports both transactional and non-transactional  tables). Keep in mind the difference between a server and a host. The server is s...

MySQL Query Browser

     MySQL Query Browser is a cross-platform GUI client program that's intuitive and easy to use. It provides a graphical interface to the MySQL server for querying and analyzing data. The MySQL Query Browser provides a Connection dialog that enables a connection to a MySQL server. This section describes how to use the Connection dialog and the Main Query Browser GUI. Using the Connection Dialog MySQL Query Browser presents a Connection dialog when it starts or when the New Instance Connection … is selected from the File menu. Connecting to a MySQL server can be accomplished either by filling in the connection dialog box fields with the parameters required to connect to a server or selecting from among any predefined connection profiles. Connection Dialog Window:                To connect to a MySQL server by specifying connection parameters directly, fill in the  appropriate fields beginning with the ...