Re: Auth module security flaw?

From: Date: Sun, 03 Feb 2002 09:19:50 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4371@lists.php.net to get a copy of this message
On 03 Feb 2002 11:01:57 +0200, Marius Andreiana wrote: >On Ma, 2002-01-29 at 16:00, Martin Jansen wrote: >> Yeah, we could introduce a function like this: >> >> ===================================================================== >> /** >> * Set customized session name >> * >> * @access public >> * @param string Name for the session >> * @return void >> */ >> function setSessionname($name = "auth") >> { >> $this->_SessionName = $name; >> } >> >> ===================================================================== >> >> $this->_SessionName is per default "auth" and users can change >> the session name to an individual value if they needs to. >> >> What do you think? >doesn't php's session_name does this, as Tomas Cox also pointed out? Ahh, I never thought of that possibility. I think the following function should fix our problem then: // {{{ setSessionname() /** * Set name of the session to a customized value. * * If you are using multiple instances of PEAR Auth * on the same domain, you can change the name of * session per application via this function. * * @access public * @param string New name for the session * @return void */ function setSessionname($name = "PHPSESSID") { @session_name($name); } // }}} What do you think? - Martin -- Martin Jansen, <mail@martin-jansen.de> http://www.martin-jansen.de/

« previous php.pear.dev (#4371) next »