PHP 4.0 Bug #8827: PHP_AUTH_PW stores password when using External Authentication

From: Date: Sun, 21 Jan 2001 06:41:08 +0000
Subject: PHP 4.0 Bug #8827: PHP_AUTH_PW stores password when using External Authentication
Groups: php.dev 
Request: Send a blank email to php-dev+get-44660@lists.php.net to get a copy of this message
From: csy@hjc.edu.sg Operating system: Redhat Linux 6.2 PHP version: 4.0.4pl1 PHP Bug Type: Apache related Bug description: PHP_AUTH_PW stores password when using External Authentication Under Apache-1.3.14 w/ php4.0.4pl1 and using auth_ldap for external authentication to an ldap server, PHP_AUTH_PW stores the password of the user that authenticates successfully. This did not occur in earlier versions of php3 and php4 and creates a problem for websites that require external authentication before accessing and the services that are provided within the websites are run by different parties as this will result in other parties getting hold of the user's password. php.ini used is similar to that which came with the php-4.0.4pl1 distribution and no settings that are changed is related to authentication. php is compiled using the following parameters :- ./configure --with-apache=/usr/src/apache_1.3.14 --with-mysql=/usr --with-dbase=yes --enable-sysvshm=yes --enable-sysvsem=yes --with-config-file-path=/usr/lib --with-system-regex=no --enable-safe-mode=yes --with-exec-dir=/usr/bin --enable-track-vars=yes --enable-magic-quotes=yes --enable-memory-limit=yes --with-ldap=/usr --with-imap=/usr --enable-ftp --with-t1lib --with-ndbm --with-db -- Edit Bug report at: http://bugs.php.net/?id=8827&edit=1

« previous php.dev (#44660) next »