【发布时间】:2010-03-20 04:55:44
【问题描述】:
我创建一个登录表单来绑定到 ldap 服务器,如果成功,它会创建一个会话(用户的用户名存储在其中),然后我转到另一个具有 session_start() 的页面;而且效果很好。
我现在想做的是添加代码来测试该用户是否是特定组的成员。
所以理论上,这就是我想做的事情
if(username session is valid) {
search ldap for user -> get list of groups user is member of
foreach(group they are member of) {
switch(group) {
case STAFF:
print 'they are member of staff group';
$access = true;
break;
default:
print 'not a member of STAFF group';
$access = false;
break;
}
if(group == STAFF) {
break;
}
}
if($access == TRUE) {
// you have access to the content on this page
} else {
// you do not have access to this page
}
}
如何进行不带绑定的 ldap_search?我不想在每个页面上一直询问他们的密码,而且我无法通过会话传递他们的密码。
感谢任何帮助。
【问题讨论】:
标签: php authentication session active-directory ldap