Re: Auth_Http backward compatibility
| From: | Philippe Jausions | Date: | Fri, 21 May 2004 19:09:24 +0000 |
| Subject: | Re: Auth_Http backward compatibility | ||
| References: | 1 | Groups: | php.pear.dev php.pear.dev php.pear.qa php.pear.qa |
| Request: | Send a blank email to pear-dev+get-29511@lists.php.net to get a copy of this message | ||
David Costa wrote:
During some extensive tests in a server running PHP 5 I discovered some other concerning issues from a security standpoint. Example : we have a scenario with 2 pages protected with AUTH_HTTP. The first page is called admin.php and the second one users.php Within admin.php AUTH_HTTP checks the table "admin_users" on the database. On users.php Auth_HTTP checks a different table or a totally different database, for example the table "registered_users" A registered user, after the access in his allowed page users.php can access admin.php without being prompted for a password (as it normally should since admin.php is checking a different table). This is due to the session sharing of Auth_HTTP.Hummm... I think this is an authorization problem, i.e. permission verification, instead of authentication, i.e. user/password verification. These two get often confused. Since this is a HTTP-based authentication packages, I would think you want to use a different Realm for the admin and user parts... However, if the users.php and admin.php files are under the same URI, then the web browser might end up getting confused. Now, if I remember correctly, the web browser doesn't send the realm back along with the credentials, so you can't have it both ways. Since the Auth package only verifies the authentication when the session is not valid (not logged in, expired and so on...) you'll need to tinker with the start() method to double check if the user authenticated against the proper the Realm. This is not so much about session sharing, but more about session selection... The improper session is used not because it is shared, but because it is not setup separately based on the Realm... However, I haven't played much with this package, so my comments may be off topic :-p -Philippe