Re: Pear Auth allows logins from all auth pages?
| From: | Matt Eaton | Date: | Fri, 16 Jan 2004 18:05:10 +0000 |
| Subject: | Re: Pear Auth allows logins from all auth pages? | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-25105@lists.php.net to get a copy of this message | ||
Perhaps a variable that says "allow logins: yes/no"?
The problem is I feel rather itchy about letting any one of my 'protected' pages also allow logins through posted variables. I'd rather there be a way just to check to see if a person is logged in. I'm sure a malicious form could do some breakage.
I don't mind making changes to my local copy of Auth. But is allowing login on any page that checks auth good default behavior?
Matt
Michael Haertl wrote:
Matt Eaton schrieb:Would an acceptible fix be: function start() {This would break bc. Some sites use this feature to have login form and Auth on different pages. Maybe you could try to extend the Auth object and integrate a logging function for your case. Mike$this->assignData();@session_start();if (!$this->checkAuth() && $this->showLogin) { $this->login(); }} (This checks if showLogin is set before attempting the log in).