Re: Auth module security flaw?
| From: | Antonio Carlos Venancio Junior | Date: | Tue, 05 Feb 2002 08:18:41 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4403@lists.php.net to get a copy of this message | ||
Marius,
At least for me the setSessionName() function will be very usefull,
escpecially because when I have like 3+ different Auth pages at the same
site (and that occurs very often ;). I would tell you to to put that
code in the class' constructor.
On 05 Feb 2002 10:03:47 +0200 Marius Andreiana
<mandreiana_lists@yahoo.com> wrote:
> On Du, 2002-02-03 at 11:19, Martin Jansen wrote:
> > // {{{ setSessionname()
> >
> > /**
> > * Set name of the session to a customized value.
> > *
> > * If you are using multiple instances of PEAR Auth
> > * on the same domain, you can change the name of
> > * session per application via this function.
> > *
> > * @access public
> > * @param string New name for the session
> > * @return void
> > */
> > function setSessionname($name = "PHPSESSID")
> > {
> > @session_name($name);
> > }
> >
> > // }}}
> >
> > What do you think?
> It works great.
>
> But now, what's the point of adding it to Auth class?
> why shouldn't one call session_name directly before
> using Auth class at all?
>
> Some sites might already have this; in that case
> auth would work from the start in the case I described.
>
> Maybe a note in Auth documentation should specify this.
Cya
Antonio
.-===================================================================-.
| Can't buy what I want because its FREE! - Pearl Jam |
|-===================================================================-|
| ICQ# 9253680 | Floripa | MySQL | PHP | FreeBSD - The Power to Serve |
`-===================================================================-'