Re: Auth module security flaw?
| From: | Martin Jansen | Date: | Tue, 29 Jan 2002 15:20:21 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4280@lists.php.net to get a copy of this message | ||
On Tue, 29 Jan 2002 15:29:43 +0100, Wolfram Kriesing wrote:
>> >why not modify Auth this way, that it uses the settings to create
>> > a unique name for the session array
>> >this would solve the problem, if the settings (or the data that
>> > are used to create the array name) for each application are
>> > different. by settings i mean parameters/options passed to the
>> > Auth-class.
>>
>> Yeah, we could introduce a function like this:
>> $this->_SessionName is per default "auth" and users can change
>> the session name to an individual value if they needs to.
>dont you mean the array name, that is written in the session?
Sorry, that was a typo on my side.
>the question here is just, if the settings are/will be different for
>every auth-instance used on the same server,
They will be different as long as the programmer calls
setSessionname with a different parameter for each auth
application on the server. If he does not call setSessionname,
the default value will be used, which may cause troubles
for him in certain situations.
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/