Auth module security flaw?

From: Date: Mon, 28 Jan 2002 17:45:20 +0000
Subject: Auth module security flaw?
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4248@lists.php.net to get a copy of this message
Hi, I have a question about Auth module. I see it registers the session variable "auth", but I don't know how will it work in case you have several applications on the save server (each with a different auth). What prevents a user, once logged in in an application, to have access to the other applications? He'll get the same session_id unless the session_id is enforced for each application to be something like $application_name . $random_string Thanks -- You don't have to go to jail for helping your neighbour http://www.gnu.org/philosophy/ _________________________________________________________ Do You Yahoo!? Get your free @yahoo.com address at http://mail.yahoo.com

« previous php.pear.dev (#4248) next »