Re: Auth_Http backward compatibility
| From: | Stefan Neufeind | Date: | Fri, 21 May 2004 13:08:00 +0000 |
| Subject: | Re: Auth_Http backward compatibility | ||
| References: | 1 | Groups: | php.pear.dev php.pear.qa |
| Request: | Send a blank email to pear-dev+get-29491@lists.php.net to get a copy of this message | ||
On 7 Apr 2004 at 21:49, David Costa wrote:
> Hello Everyone,
> With the great help of Rui Hirokawa I have completed a patch (1) in
> connection with the bug 934 (2)
> session sharing : when "users log in with the same credentials, they
> share the same session".
>
> During some extensive tests in a server running PHP 5 I discovered
> some other concerning issues from a security standpoint.
>
[...]
>
> The current patch comes out with 'sessionSharing' => true to maintain
> backward compatibility.
>
> I think that it makes sense to consider sessionSharing false by
> default, alas it will not be backward compatible.
>
> We welcome your comments and suggestions
Well, from what I heared you are right that is not really a
"feature". But I also agree that changing this behaviour would mean a
BC break. Unfortunately you already moved to a new major-version
lately ... hmm. You might consider highlighting this "good advice" to
set sessionSharing to false and explain it. But that's the best you
can do for now without a new major release. And imho releasing a new
major each half year is not a good idea :-))
I very much appreciate your security-considerations.
Kind regards,
Stefan