Re: Auth module security flaw?

From: Date: Tue, 29 Jan 2002 12:43:31 +0000
Subject: Re: Auth module security flaw?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4277@lists.php.net to get a copy of this message
> > PEAR Auth uses PHP's built-in session support. So the session > > will be only valid for the current (virtual) host. > > yes, but we don't have virtual hosts for every application, > current system uses sub-directories for them. > like www.x.org/app1, www.x.org/app2 ... why not modify Auth this way, that it uses the settings to create a unique name for the session array this would solve the problem, if the settings (or the data that are used to create the array name) for each application are different. by settings i mean parameters/options passed to the Auth-class. This way noone has to take care of the session name, just because Auth is behaving in a certain way. a unique array name would also allow to use the variable "$auth" in the code, which is not possible now, if register_globals is on. I realized that in an pearized Auth class, which additionally supports the protection of certain directories/files, which releives you from writing any auth-code in every file that needs to be protected for inspiration see http://wolfram.kriesing.de/programming/index.php#Auth -- Wolfram

« previous php.pear.dev (#4277) next »