Re: Pear Auth allows logins from all auth pages?

From: Date: Fri, 16 Jan 2004 18:05:10 +0000
Subject: Re: Pear Auth allows logins from all auth pages?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-25105@lists.php.net to get a copy of this message
Perhaps a variable that says "allow logins: yes/no"? The problem is I feel rather itchy about letting any one of my 'protected' pages also allow logins through posted variables. I'd rather there be a way just to check to see if a person is logged in. I'm sure a malicious form could do some breakage. I don't mind making changes to my local copy of Auth. But is allowing login on any page that checks auth good default behavior? Matt Michael Haertl wrote:
Matt Eaton schrieb:
Would an acceptible fix be: function start() {
       $this->assignData();
       @session_start();
       if (!$this->checkAuth() && $this->showLogin) {
           $this->login();
       }
} (This checks if showLogin is set before attempting the log in).
This would break bc. Some sites use this feature to have login form and Auth on different pages. Maybe you could try to extend the Auth object and integrate a logging function for your case. Mike


« previous php.pear.dev (#25105) next »