Re: Auth module security flaw?

From: Date: Tue, 05 Feb 2002 08:03:47 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4402@lists.php.net to get a copy of this message
On Du, 2002-02-03 at 11:19, Martin Jansen wrote: > // {{{ setSessionname() > > /** > * Set name of the session to a customized value. > * > * If you are using multiple instances of PEAR Auth > * on the same domain, you can change the name of > * session per application via this function. > * > * @access public > * @param string New name for the session > * @return void > */ > function setSessionname($name = "PHPSESSID") > { > @session_name($name); > } > > // }}} > > What do you think? It works great. But now, what's the point of adding it to Auth class? why shouldn't one call session_name directly before using Auth class at all? Some sites might already have this; in that case auth would work from the start in the case I described. Maybe a note in Auth documentation should specify this. Thanks for help! -- You don't have to go to jail for helping your neighbour http://www.gnu.org/philosophy/ _________________________________________________________ Do You Yahoo!? Get your free @yahoo.com address at http://mail.yahoo.com

« previous php.pear.dev (#4402) next »