Re: Auth module security flaw?
| From: | Bertrand Mansion | Date: | Mon, 28 Jan 2002 18:30:43 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4253@lists.php.net to get a copy of this message | ||
le 28/01/02 19:23, Bertrand Mansion à bmansion@mamasam.com a écrit :
> le 28/01/02 19:08, Marius Andreiana à mandreiana_lists@yahoo.com a écrit :
>
>> On Lu, 2002-01-28 at 19:48, Martin Jansen wrote:
>>> On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote:
>>>
>>>> I see it registers the session variable "auth", but I don't know how
>>>> will it work in case you have several applications on the save
>>>> server (each with a different auth).
>>>
>>> PEAR Auth uses PHP's built-in session support. So the session
>>> will be only valid for the current (virtual) host.
>> yes, but we don't have virtual hosts for every application,
>> current system uses sub-directories for them.
>> like www.x.org/app1, www.x.org/app2 ...
>
> I don't see where the problem is, then.
> Just define your session cookie for the whole domain and store your session
> data (variables...) in a database shared by the different applications.
> Each of them will find auth value in this db, at the row corresponding to
> your session id.
Well, maybe you want to change auth between apps ?
Then, it must be possible to set a cookie just for a specific directory...
Bertrand Mansion
Mamasam