Project

General

Profile

1
<?php
2
function login__from_env()
3
{
4
	return $_SERVER["PHP_AUTH_USER"]
5
		.($_SERVER["PHP_AUTH_PW"] !== "" ? ":".$_SERVER["PHP_AUTH_PW"] : "");
6
}
7

    
8
function user2path($user) # multiple @ and nested . OK: a@b.c@url -> url?b.c.a
9
{
10
	$path = $user;
11
	
12
	# remove padding used to visually separate elements:__x__@y__@url -> x@y@url
13
	$path = preg_replace('/\b__|__\b/', '', $path);
14
	
15
	# translate reverse @-paths into forward .-paths
16
	$path = implode(".", array_reverse(explode("@", $path)));
17
	
18
	return $path;
19
}
20

    
21
if (!isset($_SERVER["PHP_AUTH_USER"])) # browser first omits Authorization
22
{
23
	header('WWW-Authenticate: Basic realm="please leave username/password blank or as filled in"');
24
}
25
else
26
{
27
	$dest = preg_replace('!\b/!', "./", $_SERVER["SCRIPT_URI"])."?";
28
		# append trailing . to host to prevent infinite redirect loop
29
	if ($_SERVER["PHP_AUTH_USER"] !== "") # prepend to query string
30
		$dest .= "."/*force dotpath*/.user2path(login__from_env());
31
	$dest .= $_SERVER["QUERY_STRING"];
32
	
33
	header("Location: ".$dest);
34
}
35
?>
(33-33/35)