Re: Auth_Http backward compatibility

From: Date: Fri, 21 May 2004 13:08:00 +0000
Subject: Re: Auth_Http backward compatibility
References: 1  Groups: php.pear.dev php.pear.qa 
Request: Send a blank email to pear-dev+get-29491@lists.php.net to get a copy of this message
On 7 Apr 2004 at 21:49, David Costa wrote: > Hello Everyone, > With the great help of Rui Hirokawa I have completed a patch (1) in > connection with the bug 934 (2) > session sharing : when "users log in with the same credentials, they > share the same session". > > During some extensive tests in a server running PHP 5 I discovered > some other concerning issues from a security standpoint. > [...] > > The current patch comes out with 'sessionSharing' => true to maintain > backward compatibility. > > I think that it makes sense to consider sessionSharing false by > default, alas it will not be backward compatible. > > We welcome your comments and suggestions Well, from what I heared you are right that is not really a "feature". But I also agree that changing this behaviour would mean a BC break. Unfortunately you already moved to a new major-version lately ... hmm. You might consider highlighting this "good advice" to set sessionSharing to false and explain it. But that's the best you can do for now without a new major release. And imho releasing a new major each half year is not a good idea :-)) I very much appreciate your security-considerations. Kind regards, Stefan

« previous php.pear.dev (#29491) next »