Re: Pear Auth allows logins from all auth pages?
| From: | Michael Haertl | Date: | Fri, 16 Jan 2004 18:26:25 +0000 |
| Subject: | Re: Pear Auth allows logins from all auth pages? | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-25106@lists.php.net to get a copy of this message | ||
Matt Eaton schrieb:
Perhaps a variable that says "allow logins: yes/no"? The problem is I feel rather itchy about letting any one of my 'protected' pages also allow logins through posted variables. I'd rather there be a way just to check to see if a person is logged in. I'm sure a malicious form could do some breakage. I don't mind making changes to my local copy of Auth. But is allowing login on any page that checks auth good default behavior?Well, i think this was one of the design goals of Auth: To have a central authorization mechanism which automagically displays a login form whenever someone tries to access a page which needs authentication. I admit that, when i proposed to add the showLogin feature some years ago, i didn't think about your problem and i'm not sure if it's really a security issue. An "allowLogin" option defaulting to "yes" would be a solution. What do the maintainers think about this? Mike