Re: Auth module security flaw?

From: Date: Tue, 05 Feb 2002 08:18:41 +0000
Subject: Re: Auth module security flaw?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4403@lists.php.net to get a copy of this message
Marius, At least for me the setSessionName() function will be very usefull, escpecially because when I have like 3+ different Auth pages at the same site (and that occurs very often ;). I would tell you to to put that code in the class' constructor. On 05 Feb 2002 10:03:47 +0200 Marius Andreiana <mandreiana_lists@yahoo.com> wrote: > On Du, 2002-02-03 at 11:19, Martin Jansen wrote: > > // {{{ setSessionname() > > > > /** > > * Set name of the session to a customized value. > > * > > * If you are using multiple instances of PEAR Auth > > * on the same domain, you can change the name of > > * session per application via this function. > > * > > * @access public > > * @param string New name for the session > > * @return void > > */ > > function setSessionname($name = "PHPSESSID") > > { > > @session_name($name); > > } > > > > // }}} > > > > What do you think? > It works great. > > But now, what's the point of adding it to Auth class? > why shouldn't one call session_name directly before > using Auth class at all? > > Some sites might already have this; in that case > auth would work from the start in the case I described. > > Maybe a note in Auth documentation should specify this. Cya Antonio .-===================================================================-. | Can't buy what I want because its FREE! - Pearl Jam | |-===================================================================-| | ICQ# 9253680 | Floripa | MySQL | PHP | FreeBSD - The Power to Serve | `-===================================================================-'

« previous php.pear.dev (#4403) next »