Auth_Http backward compatibility

From: Date: Wed, 07 Apr 2004 19:49:33 +0000
Subject: Auth_Http backward compatibility
Groups: php.pear.dev php.pear.qa 
Request: Send a blank email to pear-dev+get-27137@lists.php.net to get a copy of this message
Hello Everyone, With the great help of Rui Hirokawa I have completed a patch (1) in connection with the bug 934 (2) session sharing : when "users log in with the same credentials, they share the same session". During some extensive tests in a server running PHP 5 I discovered some other concerning issues from a security standpoint. Example : we have a scenario with 2 pages protected with AUTH_HTTP. The first page is called admin.php and the second one users.php Within admin.php AUTH_HTTP checks the table "admin_users" on the database. On users.php Auth_HTTP checks a different table or a totally different database, for example the table "registered_users" A registered user, after the access in his allowed page users.php can access admin.php without being prompted for a password (as it normally should since admin.php is checking a different table). This is due to the session sharing of Auth_HTTP. The current patch comes out with 'sessionSharing' => true to maintain backward compatibility. I think that it makes sense to consider sessionSharing false by default, alas it will not be backward compatible. We welcome your comments and suggestions Thanks in advance for your time and attention, Regards, David Costa, Dotgeek.org
PHP-PostgreSQL Advocacy team     http://dotgeek.org
gurugeek att php dot net david at postgresql ddoot org 1) http://cvs.php.net/diff.php/pear/Auth_HTTP/Auth_HTTP.php?login=2&r1=1.12&r2=1.13&ty=h&num=10 2) http://pear.php.net/bugs/bug.php?id=934

« previous php.pear.dev (#27137) next »