Re: Auth module security flaw?

From: Date: Mon, 28 Jan 2002 18:30:43 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4253@lists.php.net to get a copy of this message
le 28/01/02 19:23, Bertrand Mansion à bmansion@mamasam.com a écrit : > le 28/01/02 19:08, Marius Andreiana à mandreiana_lists@yahoo.com a écrit : > >> On Lu, 2002-01-28 at 19:48, Martin Jansen wrote: >>> On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote: >>> >>>> I see it registers the session variable "auth", but I don't know how >>>> will it work in case you have several applications on the save >>>> server (each with a different auth). >>> >>> PEAR Auth uses PHP's built-in session support. So the session >>> will be only valid for the current (virtual) host. >> yes, but we don't have virtual hosts for every application, >> current system uses sub-directories for them. >> like www.x.org/app1, www.x.org/app2 ... > > I don't see where the problem is, then. > Just define your session cookie for the whole domain and store your session > data (variables...) in a database shared by the different applications. > Each of them will find auth value in this db, at the row corresponding to > your session id. Well, maybe you want to change auth between apps ? Then, it must be possible to set a cookie just for a specific directory... Bertrand Mansion Mamasam

« previous php.pear.dev (#4253) next »