Re: Auth module security flaw?

From: Date: Tue, 05 Feb 2002 10:34:01 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4416@lists.php.net to get a copy of this message
le 5/02/02 11:05, Marius Andreiana à mandreiana_lists@yahoo.com a écrit : > On Ma, 2002-02-05 at 11:39, Bertrand Mansion wrote: >> As I expected, Auth and Sessions are closely tied together. >> IMHO, if you call session_name in the constructor, you should also be >> allowed to call session_set_cookie_params and customize your session for the >> authentication. >> >> IMO, we should have a session class in PEAR to handle all this. > yes, this would be the best approach. > > Would be great to include in it the functionality which is in > http://sourceforge.net/projects/pearsession This problem I see with your implementation is that it doesn't allow different containers like LDAP or DBM or proprietary format... I think you should make a class of this and have a session object using different containers just like in PHPLib. This way you could call specific methods of your own, for instance your own serializer or encoder... I made a try but it is far from perfect: Main class: http://www.mamasam.com/develop/session/Session.phps Container DB_Split: http://www.mamasam.com/develop/session/Container/DB_Split.phps I don't have time to develop more containers but this is an easy task. If someone feels playing with the code, fell at home. Regards, Bertrand Mansion Mamasam

« previous php.pear.dev (#4416) next »