Solved

Password authentication script

Posted on 1997-05-11
4
289 Views
Last Modified: 2013-12-25
I require to get a Username/Password from a user and then use the username for other scripts.  I am on an ISP running BSD Unix. I have set up htaccess in the appropriate secure directories and it work fine, but when I run a script after the user has logged in, the "REMOTE_USER" enviroment variable is always blank, so I have no way of knowing who the user is.  As I am using an ISP, I have no control of the server configuration.
Could I put in a cgi script to replace .htaccess? (Sample please)
Is there any reason why I cannot read "REMOTE_USER"?
 
0
Comment
Question by:ninoc
  • 2
  • 2
4 Comments
 
LVL 5

Accepted Solution

by:
icd earned 50 total points
ID: 1828002
If you don't want to use .htaccess then you *could* use a script but the security will not be so good.

You could pass the username from one script to the next using the GET method. The only drawback is that if you accessed an html document (not generated from a script) you would lose it so all your documents would have to be generated from cgi.

Alternatively put the user name in a cookie which would be available to each page with javascript. Unfortunately not all browsers use cookies and some people even disable them.

If you did not need to be absolutely certain of the user you could use the REMOTE_ADDR to determine who was accessing the page. They would log on, give their name and password which you would verify and record against it (in a log file) the REMOTE_ADDR. When a script is run you obtain the REMOTE_ADDR, look it up in the log file and carry out the appropriate action.

The REMOTE_ADDR will not always be the same for the same person since some systems allocate them to users from a 'pool' of numbers and sometimes different people will have the same REMOTE_ADDR for the same reason. But for the short period of time that a person is browsing your site it will be useful.
0
 
LVL 5

Expert Comment

by:icd
ID: 1828003
If the cgi is as a result of a form, try changing the method. (e.g. from POST to GET) and see what happens. I came across this comment:-

If you only use GET protection for a CGI script, you may be finding that the REMOTE_USER environment variable is not
getting set when using METHOD="POST", obviously because the directory isn't protected against POST.
0
 

Expert Comment

by:ritesh081398
ID: 1828004
One solution to this problem will be to add the accepted username into a temporary file
or a temp variable through a cgi script and use that value as a remote_user
0
 

Expert Comment

by:ritesh081398
ID: 1828005

B00042-patch.correct_user_logging.v2

        [This patch supercedes B00042-patch.correct_user_logging, which I
        managed to screw up!]

Version Apache/0.3

The common logfile's 'user' (3rd) field is meant to contain the user
supplied user-id which matches the value held in .htaccess files.
 
If the file has server-side includes (ie it's a u+x or .shtml file) then
I find that the 'user' entry is recorded as '-', even though a uid/pwd
is required and given for the main including file.
 
This patch changes http_access.c, http_log.c and http_request.c.  Add
        -DLOGUSER
to the Makefile's compile-time flags to change the server's behaviour.
 
Ay.

*** http_auth.c.dist    Tue Mar 28 14:01:46 1995
--- http_auth.c Wed Mar 29 12:51:59 1995
***************
*** 46,51 ****
--- 46,59 ----
      }
  }
 
+
+ #ifdef LOGUSER
+       /* B00042
+        * Keep a copy of the first 'user' id provided for .htaccess
+        */
+       extern char log_user[MAX_STRING_LEN];
+ #endif
+
  void check_auth(security_data *sec, int m, FILE *out) {
      char at[MAX_STRING_LEN];
      char ad[MAX_STRING_LEN];
***************
*** 79,84 ****
--- 87,100 ----
              auth_bong("type mismatch",out);
          uudecode(t,(unsigned char *)ad,MAX_STRING_LEN);
          getword(user,ad,':');
+ #ifdef LOGUSER
+       /* B00042
+        * Keep a copy of the first 'user' id provided for .htaccess
+        */
+       if ( log_user[0] == '\0' ) {
+               strcpy( log_user, user );
+       };
+ #endif
          strcpy(sent_pw,ad);
          if(!get_pw(user,real_pw,out)) {
              sprintf(errstr,"user %s not found",user);
*** http_log.c.dist     Wed Mar 29 12:31:22 1995
--- http_log.c  Wed Mar 29 12:51:55 1995
***************
*** 60,65 ****
--- 60,72 ----
      strcpy(the_request,cmd_line);
  }
 
+ #ifdef LOGUSER
+       /* B00042
+        * Keep a copy of the first 'user' id provided for .htaccess
+        */
+       extern char log_user[MAX_STRING_LEN];
+ #endif
+
  void log_transaction() {
      char str[HUGE_STRING_LEN];
      long timz;
***************
*** 76,82 ****
--- 83,96 ----
      sprintf(str,"%s %s %s [%s %c%02d%02d] \"%s\" ",
              remote_name,
              (do_rfc931 ? remote_logname : "-"),
+ #ifdef LOGUSER
+       /* B00042
+        * Keep a copy of the first 'user' id provided for .htaccess
+        */
+            (log_user[0] ? log_user : "-"),
+ #else
              (user[0] ? user : "-"),
+ #endif
              tstr,
              sign,
              timz/3600,
*** http_request.c.dist Tue Mar 28 13:54:54 1995
--- http_request.c      Wed Mar 29 12:39:29 1995
***************
*** 95,100 ****
--- 95,107 ----
      return 0;
  }
 
+ #ifdef LOGUSER
+       /* B00042
+        * Keep a copy of the first 'user' id provided for .htaccess
+        */
+       char log_user[MAX_STRING_LEN];
+ #endif
+
  void process_request(int in, FILE *out) {
      char m[HUGE_STRING_LEN];
      char w[HUGE_STRING_LEN];
***************
*** 102,107 ****
--- 109,121 ----
      char url[HUGE_STRING_LEN];
      char args[HUGE_STRING_LEN];
      int s,n;
+
+ #ifdef LOGUSER
+       /* B00042
+        * Keep a copy of the first 'user' id provided for .htaccess
+        */
+       log_user[0] = '\0';
+ #endif
 
      get_remote_host(in);
      exit_callback = NULL;
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
copy-item script help 15 84
Need a good Angular tutorial 5 87
What is assert.deepEqual? 4 59
Transform normalized CSV to line in powershell 7 49
In this tutorial I will show you how to provide a dynamic RTF document on your website generated with data from your database. For this tutorial you will need Microsoft Word or WordPad, WhizBase and Microsoft Access. In this tutorial I will show …
Active Directory replication delay is the cause to many problems.  Here is a super easy script to force Active Directory replication to all sites with by using an elevated PowerShell command prompt, and a tool to verify your changes.
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question