Re: Auth module security flaw?
| From: | Wolfram Kriesing | Date: | Tue, 29 Jan 2002 14:29:43 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4279@lists.php.net to get a copy of this message | ||
> >why not modify Auth this way, that it uses the settings to create
> > a unique name for the session array
> >this would solve the problem, if the settings (or the data that
> > are used to create the array name) for each application are
> > different. by settings i mean parameters/options passed to the
> > Auth-class.
>
> Yeah, we could introduce a function like this:
> $this->_SessionName is per default "auth" and users can change
> the session name to an individual value if they needs to.
dont you mean the array name, that is written in the session?
why not, would work fine for most people i guess,
but it's not what i meant
i meant to generate the array name that is written in the session
(now it's 'auth')
this would require to change the code in quite some places from
$_SESSION['auth']...
to something like
$_SESSION[ $this->sessionArrayName ]....
but that should be a simple "replace all" in any editor
this way the user wont be bothered with any of this stuff either.
the question here is just, if the settings are/will be different for
every auth-instance used on the same server, or what is used to
genereate the session-array name
in the method "setup" the second block, is where i am doing it, feel
free to check it out at:
http://www.kriesing.de/showsource.php?domain=wolfram.kriesing.de&file
=/libs/php/Auth/common.php
--
Wolfram