The main objection that I have to .htaccess files being used as authentication is that I know of no convenient way to time them out (I'd love to hear a rebuttal of that!!!). This can be a huge security hole.
Second, unless you are using Digest Authentication (which is not widely supported), then the username and password are sent using Basic Authentication in what is essentially plain text. If you use this method, be sure to serve the pages via a secure connection and make sure that the cookies will only be returned over a secure connection.
Cheers,
Ovid
Join the Perlmonks Setiathome Group or just click on the the link and check out our stats.
In reply to (Ovid) Re: Integrating Script with .htaccess
by Ovid
in thread Integrating Script with .htaccess
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |