Sometimes you want to secure a particular webpage, but don't want to manage users or accounts, write a separate
login page, etc. The easy way to authenticate is to use HTTP's WWW-Authenticate response header:
<?php
$nouser = empty($_SERVER['PHP_AUTH_USER']) || ($_SERVER['PHP_AUTH_USER'] != 'MyUsername');
$nopass = empty($_SERVER['PHP_AUTH_PW']) || ($_SERVER['PHP_AUTH_PW'] != 'MyPassword');
if ($nouser || $nopass) {
header('WWW-Authenticate: Basic realm="Geekworks Unlimited, LLC."');
header('HTTP/1.0 401 Unauthorized');
echo '<h1>HTTP/1.0 401 Unauthorized</h1>';
} else {
?>
<!DOCTYPE html>
<html>
<head>
<title>My Secret Website</title>
</head>
<body>
Your website content goes here.
</body>
</html>
<?php
}
exit;
?>
This checks against a single (hardcoded) username and password, which is fine in simple cases. If you
do need to give each user his or her own username and password, you can replace the first
two lines with a loop that checks $_SERVER['PHP_AUTH_USER'] and $_SERVER['PHP_AUTH_PW']
against values in your user database.
One note: You will want to change where it says realm="...". This message is shown in the
popup that asks the visitor to input a username and password. It also serves as a possible set of pages to
authenticate against. If you include the same realm on multiple pages, the user will only have
to log in once in order to visit all of the pages.
I'm a Front-End Engineer at Yahoo! working on the Mail and Messenger teams. I blog about web design and development topics including accessibility, usability, performance, and developing HTML / CSS / JavaScript applications on Appcelerator Titanium and Adobe AIR.
If you're a web developer, you might enjoy Jelo, my JavaScript library.
A few panoramic shots I took at SDCC 2010. #geek http://bit.ly/bwX6GB
JS version of Regex prime number checker:
function isPrime(n) {
return Array(n + 1).join("1")
.search(/^1?$|^(11+?)\1+$/) == -1;
}
Погрузился в пучину EcmaScript5, местами увлекательно, местами нудно =)
Modernizr http://ow.ly/18njQ1
A Collection of 20 HTML5 Video Players - a round-up of JavaScript and html5 alternatives to Flash-based media player... http://ow.ly/18njQ2
jQuery TOOLS - The missing UI library for the Web http://ow.ly/18njQ3
Contactable - A jQuery Plugin | the odin http://ow.ly/18njQ4
Giants vs Dodgers, sweet seats. http://twitpic.com/2ag9pa
@snookca That'll be fixed next week. I promise.
@snookca I was tryna not name names ;) But really that was just par for the course today, pretty hectic day. As I'm sure you know.
Who breaks major stuff after 4pm on Friday? On the last day of the sprint, no less. Tsk. (wasn't me)
Awesome live git tracker for teams: http://www.utsup.com/
RT @DerrenBrown: Blog post: Camera Software Lets You See Into the Past http://bit.ly/9kjVg5
10 invites to the new version of Digg: http://bit.ly/dqM8EV
Threaded vs Evented Servers, great look at the whats and whys. http://bit.ly/bDUEjn #geek
Nav, Context menus, "app-style" toolbars in sample chapter http://bit.ly/csTRY8 of new YUI book http://bit.ly/cJINoV
Add a side-mounted End Call button to your iPhone 4: http://bit.ly/cGxPBD #funny #geekAll original work on this site is covered by a Creative Commons Attribution 3.0 license unless otherwise specified.
You may share or use any code or images from this site in any manner, for free, so long as reasonable effort has been made to give credit where due.
The views expressed in the posts and comments on this blog do not necessarily reflect the views of Yahoo!