Re: Auth module security flaw?
| From: | Marius Andreiana | Date: | Mon, 28 Jan 2002 18:08:56 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4250@lists.php.net to get a copy of this message | ||
On Lu, 2002-01-28 at 19:48, Martin Jansen wrote:
> On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote:
>
> >I see it registers the session variable "auth", but I don't know how
> >will it work in case you have several applications on the save
> >server (each with a different auth).
>
> PEAR Auth uses PHP's built-in session support. So the session
> will be only valid for the current (virtual) host.
yes, but we don't have virtual hosts for every application,
current system uses sub-directories for them.
like www.x.org/app1, www.x.org/app2 ...
--
You don't have to go to jail for helping your neighbour
http://www.gnu.org/philosophy/
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com