in reply to site access: Apache Basic auth vs. CGI::Session and cookies
Normally browsers will keep issuing authorization headers to the server and maintain their authorized state because while the HTTP protocol defines authorization schemes unfortunately there is no common un-authorization scheme defined.
Here's where cookies and the likes can help. The server side can influence the validity and content of a cookie. Just set a cookie to a 'logout' status when the user requests to logout and the next roundtrip the browser issues an authorization header then decline the validity of that header.
There are many modules on CPAN that combine basic authentication with cookies (or even sessions) to get this result.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: site access: Apache Basic auth vs. CGI::Session and cookies
by j3 (Friar) on Apr 10, 2007 at 07:12 UTC | |
by varian (Chaplain) on Apr 10, 2007 at 14:05 UTC | |
by j3 (Friar) on Apr 10, 2007 at 16:02 UTC |