Re: Auth module security flaw?
| From: | Marius Andreiana | Date: | Tue, 05 Feb 2002 08:03:47 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4402@lists.php.net to get a copy of this message | ||
On Du, 2002-02-03 at 11:19, Martin Jansen wrote:
> // {{{ setSessionname()
>
> /**
> * Set name of the session to a customized value.
> *
> * If you are using multiple instances of PEAR Auth
> * on the same domain, you can change the name of
> * session per application via this function.
> *
> * @access public
> * @param string New name for the session
> * @return void
> */
> function setSessionname($name = "PHPSESSID")
> {
> @session_name($name);
> }
>
> // }}}
>
> What do you think?
It works great.
But now, what's the point of adding it to Auth class?
why shouldn't one call session_name directly before
using Auth class at all?
Some sites might already have this; in that case
auth would work from the start in the case I described.
Maybe a note in Auth documentation should specify this.
Thanks for help!
--
You don't have to go to jail for helping your neighbour
http://www.gnu.org/philosophy/
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com