Re: Auth module security flaw?

From: Date: Mon, 28 Jan 2002 17:48:48 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4249@lists.php.net to get a copy of this message
On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote: >I see it registers the session variable "auth", but I don't know how >will it work in case you have several applications on the save >server (each with a different auth). PEAR Auth uses PHP's built-in session support. So the session will be only valid for the current (virtual) host. If one logs in on host a and then changes to host b, where PEAR Auth is also running, he will need to log in again, because the former session is only valid for host a and not for host b. - Martin -- Martin Jansen, <mail@martin-jansen.de> http://www.martin-jansen.de/

« previous php.pear.dev (#4249) next »