[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Status & CVS & objects



We obviously have a lot to talk about regarding authentication.

No one seems to be agreeing.  We could just ditch http_auth altogether and
go back to some kinda custom auth scheme... 

I don't know enuf about http_auth to talk about it much.  I need to school
myself or have someone explain it all to me before I say much more...

Jason


On Thu, Nov 04, 1999 at 01:34:07PM -0800, Micah K Yoder wrote:
> Jason Pincin wrote:
> 
> > Yeh - we can't require cookies.  crypt is cool - I assume your going to be
> > storing passwords via php's crypt() function then?  Cool.
> 
> Right on.
> 
> > As far as authentication... cookies are optional.  But we are using httpauth in
> > order to have session level authentication.  I want someone to come up with a
> > way to do this in php so an auth doesn't take TWO connections to the DB, as now
> > it requires one php and one mod_perl.
> 
> Yes, http authentication is easy in PHP.  Actually I thought we *were*
> doing it that way...  are we not?
> 
> > What we are making optional with cookies (and thus you should account for on
> > signup) is:  if the user chooses to accept an account cookie - they won't have
> > to login every time they return to the site to restore there preferences.
> 
> Actually (correct me if I'm wrong) I don't think it's possible to mix
> cookies and HTTP authentication!  They can't be mixed, at least not
> trivially.  I guess we can check if they have the cookie, and if not
> check HTTP auth.
> 
> > At any rate - my point is - this should be disabled for users with advanced
> > privleges.  People with admin access to branches of the tree should not be
> > allowed to store auth cookies methinks.  Someone finds out, walks up to there
> > browser, and voila - hoses our tree.
> 
> Actually (again correct me if I'm wrong) that's a problem with HTTP
> auth.  Once you're authenticated on a server, the login is valid until
> you close the browser!  Is there a way to erase the login info without
> closing the browser?  If so, I'd *really* like to know about it.
> 
> Later,
> Micah

-- 
Jason
http://vodka.linuxkb.org/~chardros