Re: Pear Auth allows logins from all auth pages?

From: Date: Fri, 16 Jan 2004 18:26:25 +0000
Subject: Re: Pear Auth allows logins from all auth pages?
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-25106@lists.php.net to get a copy of this message
Matt Eaton schrieb:
Perhaps a variable that says "allow logins: yes/no"? The problem is I feel rather itchy about letting any one of my 'protected' pages also allow logins through posted variables. I'd rather there be a way just to check to see if a person is logged in. I'm sure a malicious form could do some breakage. I don't mind making changes to my local copy of Auth. But is allowing login on any page that checks auth good default behavior?
Well, i think this was one of the design goals of Auth: To have a central authorization mechanism which automagically displays a login form whenever someone tries to access a page which needs authentication. I admit that, when i proposed to add the showLogin feature some years ago, i didn't think about your problem and i'm not sure if it's really a security issue. An "allowLogin" option defaulting to "yes" would be a solution. What do the maintainers think about this? Mike

« previous php.pear.dev (#25106) next »