PHP 4.0 Bug #8827: PHP_AUTH_PW stores password when using External Authentication
| From: | csy at hjc dot edu dot sg | Date: | Sun, 21 Jan 2001 06:41:08 +0000 |
| Subject: | PHP 4.0 Bug #8827: PHP_AUTH_PW stores password when using External Authentication | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-44660@lists.php.net to get a copy of this message | ||
From: csy@hjc.edu.sg
Operating system: Redhat Linux 6.2
PHP version: 4.0.4pl1
PHP Bug Type: Apache related
Bug description: PHP_AUTH_PW stores password when using External Authentication
Under Apache-1.3.14 w/ php4.0.4pl1 and using auth_ldap for external authentication to an ldap
server, PHP_AUTH_PW stores the password of the user that authenticates successfully.
This did not occur in earlier versions of php3 and php4 and creates a problem for websites that
require external authentication before accessing and the services that are provided within the
websites are run by different parties as this will result in other parties getting hold of the
user's password.
php.ini used is similar to that which came with the php-4.0.4pl1 distribution and no settings that
are changed is related to authentication.
php is compiled using the following parameters :-
./configure
--with-apache=/usr/src/apache_1.3.14
--with-mysql=/usr
--with-dbase=yes
--enable-sysvshm=yes
--enable-sysvsem=yes
--with-config-file-path=/usr/lib
--with-system-regex=no
--enable-safe-mode=yes
--with-exec-dir=/usr/bin
--enable-track-vars=yes
--enable-magic-quotes=yes
--enable-memory-limit=yes
--with-ldap=/usr
--with-imap=/usr
--enable-ftp
--with-t1lib
--with-ndbm
--with-db
--
Edit Bug report at: http://bugs.php.net/?id=8827&edit=1