Re: Auth module security flaw?

From: Date: Tue, 29 Jan 2002 15:20:21 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4280@lists.php.net to get a copy of this message
On Tue, 29 Jan 2002 15:29:43 +0100, Wolfram Kriesing wrote: >> >why not modify Auth this way, that it uses the settings to create >> > a unique name for the session array >> >this would solve the problem, if the settings (or the data that >> > are used to create the array name) for each application are >> > different. by settings i mean parameters/options passed to the >> > Auth-class. >> >> Yeah, we could introduce a function like this: >> $this->_SessionName is per default "auth" and users can change >> the session name to an individual value if they needs to. >dont you mean the array name, that is written in the session? Sorry, that was a typo on my side. >the question here is just, if the settings are/will be different for >every auth-instance used on the same server, They will be different as long as the programmer calls setSessionname with a different parameter for each auth application on the server. If he does not call setSessionname, the default value will be used, which may cause troubles for him in certain situations. - Martin -- Martin Jansen, <mail@martin-jansen.de> http://www.martin-jansen.de/

« previous php.pear.dev (#4280) next »