Auth_Http backward compatibility
| From: | David Costa | Date: | Wed, 07 Apr 2004 19:49:33 +0000 |
| Subject: | Auth_Http backward compatibility | ||
| Groups: | php.pear.dev php.pear.qa | ||
| Request: | Send a blank email to pear-dev+get-27137@lists.php.net to get a copy of this message | ||
Hello Everyone,
With the great help of Rui Hirokawa I have completed a patch (1) in connection with the bug 934 (2)
session sharing : when "users log in with the same credentials, they share the same session".
During some extensive tests in a server running PHP 5 I discovered some other concerning issues from a security standpoint.
Example : we have a scenario with 2 pages protected with AUTH_HTTP. The first page is called
admin.php and the second one users.php
Within admin.php AUTH_HTTP checks the table "admin_users" on the database.
On users.php Auth_HTTP checks a different table or a totally different database, for example the table "registered_users"
A registered user, after the access in his allowed page users.php can access admin.php without being prompted for a password (as it normally should
since admin.php is checking a different table).
This is due to the session sharing of Auth_HTTP.
The current patch comes out with 'sessionSharing' => true to maintain backward compatibility.
I think that it makes sense to consider sessionSharing false by default, alas it will not be backward compatible.
We welcome your comments and suggestions
Thanks in advance for your time and attention,
Regards,
David Costa, Dotgeek.org
PHP-PostgreSQL Advocacy team http://dotgeek.orggurugeek att php dot net david at postgresql ddoot org 1) http://cvs.php.net/diff.php/pear/Auth_HTTP/Auth_HTTP.php?login=2&r1=1.12&r2=1.13&ty=h&num=10 2) http://pear.php.net/bugs/bug.php?id=934