Re: Auth module security flaw?
| From: | Bertrand Mansion | Date: | Tue, 05 Feb 2002 10:34:01 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4416@lists.php.net to get a copy of this message | ||
le 5/02/02 11:05, Marius Andreiana à mandreiana_lists@yahoo.com a écrit :
> On Ma, 2002-02-05 at 11:39, Bertrand Mansion wrote:
>> As I expected, Auth and Sessions are closely tied together.
>> IMHO, if you call session_name in the constructor, you should also be
>> allowed to call session_set_cookie_params and customize your session for the
>> authentication.
>>
>> IMO, we should have a session class in PEAR to handle all this.
> yes, this would be the best approach.
>
> Would be great to include in it the functionality which is in
> http://sourceforge.net/projects/pearsession
This problem I see with your implementation is that it doesn't allow
different containers like LDAP or DBM or proprietary format...
I think you should make a class of this and have a session object using
different containers just like in PHPLib. This way you could call specific
methods of your own, for instance your own serializer or encoder...
I made a try but it is far from perfect:
Main class:
http://www.mamasam.com/develop/session/Session.phps
Container DB_Split:
http://www.mamasam.com/develop/session/Container/DB_Split.phps
I don't have time to develop more containers but this is an easy task. If
someone feels playing with the code, fell at home.
Regards,
Bertrand Mansion
Mamasam