Re: Auth module security flaw?
| From: | Tomas V.V.Cox | Date: | Mon, 28 Jan 2002 20:33:51 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4256@lists.php.net to get a copy of this message | ||
El lun, 28-01-2002 a las 19:08, Marius Andreiana escribió:
> On Lu, 2002-01-28 at 19:48, Martin Jansen wrote:
> > On 28 Jan 2002 19:45:20 +0200, Marius Andreiana wrote:
> >
> > >I see it registers the session variable "auth", but I don't know how
> > >will it work in case you have several applications on the save
> > >server (each with a different auth).
> >
> > PEAR Auth uses PHP's built-in session support. So the session
> > will be only valid for the current (virtual) host.
> yes, but we don't have virtual hosts for every application,
> current system uses sub-directories for them.
> like www.x.org/app1, www.x.org/app2 ...
>
Use session_name('app1') for that.
Tomas V.V.Cox