Re: Auth module security flaw?
| From: | Martin Jansen | Date: | Tue, 29 Jan 2002 14:00:03 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4278@lists.php.net to get a copy of this message | ||
On Tue, 29 Jan 2002 13:43:31 +0100, Wolfram Kriesing wrote:
>> > PEAR Auth uses PHP's built-in session support. So the session
>> > will be only valid for the current (virtual) host.
>>
>> yes, but we don't have virtual hosts for every application,
>> current system uses sub-directories for them.
>> like www.x.org/app1, www.x.org/app2 ...
>
>why not modify Auth this way, that it uses the settings to create a
>unique name for the session array
>this would solve the problem, if the settings (or the data that are
>used to create the array name) for each application are different.
>by settings i mean parameters/options passed to the Auth-class.
Yeah, we could introduce a function like this:
=====================================================================
/**
* Set customized session name
*
* @access public
* @param string Name for the session
* @return void
*/
function setSessionname($name = "auth")
{
$this->_SessionName = $name;
}
=====================================================================
$this->_SessionName is per default "auth" and users can change
the session name to an individual value if they needs to.
What do you think?
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/