Re: Auth module security flaw?
| From: | Bertrand Mansion | Date: | Tue, 05 Feb 2002 09:39:26 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4410@lists.php.net to get a copy of this message | ||
le 5/02/02 9:33, Marius Andreiana à mandreiana_lists@yahoo.com a écrit :
> On Ma, 2002-02-05 at 10:18, Antonio Carlos Venancio Junior wrote:
>> At least for me the setSessionName() function will be very usefull,
>> escpecially because when I have like 3+ different Auth pages at the same
>> site (and that occurs very often ;). I would tell you to to put that
>> code in the class' constructor.
> Having it in the constructor would also help me by not having to
> write an extra line with session_name() :-)
As I expected, Auth and Sessions are closely tied together.
IMHO, if you call session_name in the constructor, you should also be
allowed to call session_set_cookie_params and customize your session for the
authentication.
IMO, we should have a session class in PEAR to handle all this.
Bertrand Mansion
Mamasam