[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Status & CVS & objects
We obviously have a lot to talk about regarding authentication.
No one seems to be agreeing. We could just ditch http_auth altogether and
go back to some kinda custom auth scheme...
I don't know enuf about http_auth to talk about it much. I need to school
myself or have someone explain it all to me before I say much more...
Jason
On Thu, Nov 04, 1999 at 01:34:07PM -0800, Micah K Yoder wrote:
> Jason Pincin wrote:
>
> > Yeh - we can't require cookies. crypt is cool - I assume your going to be
> > storing passwords via php's crypt() function then? Cool.
>
> Right on.
>
> > As far as authentication... cookies are optional. But we are using httpauth in
> > order to have session level authentication. I want someone to come up with a
> > way to do this in php so an auth doesn't take TWO connections to the DB, as now
> > it requires one php and one mod_perl.
>
> Yes, http authentication is easy in PHP. Actually I thought we *were*
> doing it that way... are we not?
>
> > What we are making optional with cookies (and thus you should account for on
> > signup) is: if the user chooses to accept an account cookie - they won't have
> > to login every time they return to the site to restore there preferences.
>
> Actually (correct me if I'm wrong) I don't think it's possible to mix
> cookies and HTTP authentication! They can't be mixed, at least not
> trivially. I guess we can check if they have the cookie, and if not
> check HTTP auth.
>
> > At any rate - my point is - this should be disabled for users with advanced
> > privleges. People with admin access to branches of the tree should not be
> > allowed to store auth cookies methinks. Someone finds out, walks up to there
> > browser, and voila - hoses our tree.
>
> Actually (again correct me if I'm wrong) that's a problem with HTTP
> auth. Once you're authenticated on a server, the login is valid until
> you close the browser! Is there a way to erase the login info without
> closing the browser? If so, I'd *really* like to know about it.
>
> Later,
> Micah
--
Jason
http://vodka.linuxkb.org/~chardros