Re: Auth module security flaw?
| From: | Wolfram Kriesing | Date: | Tue, 29 Jan 2002 12:43:31 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4277@lists.php.net to get a copy of this message | ||
> > PEAR Auth uses PHP's built-in session support. So the session
> > will be only valid for the current (virtual) host.
>
> yes, but we don't have virtual hosts for every application,
> current system uses sub-directories for them.
> like www.x.org/app1, www.x.org/app2 ...
why not modify Auth this way, that it uses the settings to create a
unique name for the session array
this would solve the problem, if the settings (or the data that are
used to create the array name) for each application are different.
by settings i mean parameters/options passed to the Auth-class.
This way noone has to take care of the session name, just because
Auth is behaving in a certain way.
a unique array name would also allow to use the variable "$auth" in
the code, which is not possible now, if register_globals is on.
I realized that in an pearized Auth class, which additionally
supports the protection of certain directories/files, which releives
you from writing any auth-code in every file that needs to be
protected
for inspiration see
http://wolfram.kriesing.de/programming/index.php#Auth
--
Wolfram