Re: Auth module security flaw?
| From: | Martin Jansen | Date: | Mon, 28 Jan 2002 17:48:48 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4249@lists.php.net to get a copy of this message | ||
On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote:
>I see it registers the session variable "auth", but I don't know how
>will it work in case you have several applications on the save
>server (each with a different auth).
PEAR Auth uses PHP's built-in session support. So the session
will be only valid for the current (virtual) host. If one
logs in on host a and then changes to host b, where PEAR Auth
is also running, he will need to log in again, because the
former session is only valid for host a and not for host b.
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/