Re: Auth module security flaw?

From: Date: Mon, 28 Jan 2002 20:33:51 +0000
Subject: Re: Auth module security flaw?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4256@lists.php.net to get a copy of this message
El lun, 28-01-2002 a las 19:08, Marius Andreiana escribió: > On Lu, 2002-01-28 at 19:48, Martin Jansen wrote: > > On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote: > > > > >I see it registers the session variable "auth", but I don't know how > > >will it work in case you have several applications on the save > > >server (each with a different auth). > > > > PEAR Auth uses PHP's built-in session support. So the session > > will be only valid for the current (virtual) host. > yes, but we don't have virtual hosts for every application, > current system uses sub-directories for them. > like www.x.org/app1, www.x.org/app2 ... > Use session_name('app1') for that. Tomas V.V.Cox

« previous php.pear.dev (#4256) next »