Re: Auth module security flaw?
| From: | Martin Jansen | Date: | Sun, 03 Feb 2002 09:19:50 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4371@lists.php.net to get a copy of this message | ||
On 03 Feb 2002 11:01:57 +0200, Marius Andreiana wrote:
>On Ma, 2002-01-29 at 16:00, Martin Jansen wrote:
>> Yeah, we could introduce a function like this:
>>
>> =====================================================================
>> /**
>> * Set customized session name
>> *
>> * @access public
>> * @param string Name for the session
>> * @return void
>> */
>> function setSessionname($name = "auth")
>> {
>> $this->_SessionName = $name;
>> }
>>
>> =====================================================================
>>
>> $this->_SessionName is per default "auth" and users can change
>> the session name to an individual value if they needs to.
>>
>> What do you think?
>doesn't php's session_name does this, as Tomas Cox also pointed out?
Ahh, I never thought of that possibility. I think the following
function should fix our problem then:
// {{{ setSessionname()
/**
* Set name of the session to a customized value.
*
* If you are using multiple instances of PEAR Auth
* on the same domain, you can change the name of
* session per application via this function.
*
* @access public
* @param string New name for the session
* @return void
*/
function setSessionname($name = "PHPSESSID")
{
@session_name($name);
}
// }}}
What do you think?
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/