Re: Auth module security flaw?

From: Date: Tue, 29 Jan 2002 14:00:03 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4278@lists.php.net to get a copy of this message
On Tue, 29 Jan 2002 13:43:31 +0100, Wolfram Kriesing wrote: >> > PEAR Auth uses PHP's built-in session support. So the session >> > will be only valid for the current (virtual) host. >> >> yes, but we don't have virtual hosts for every application, >> current system uses sub-directories for them. >> like www.x.org/app1, www.x.org/app2 ... > >why not modify Auth this way, that it uses the settings to create a >unique name for the session array >this would solve the problem, if the settings (or the data that are >used to create the array name) for each application are different. >by settings i mean parameters/options passed to the Auth-class. Yeah, we could introduce a function like this: ===================================================================== /** * Set customized session name * * @access public * @param string Name for the session * @return void */ function setSessionname($name = "auth") { $this->_SessionName = $name; } ===================================================================== $this->_SessionName is per default "auth" and users can change the session name to an individual value if they needs to. What do you think? - Martin -- Martin Jansen, <mail@martin-jansen.de> http://www.martin-jansen.de/

« previous php.pear.dev (#4278) next »