Re: Auth module security flaw?

From: Date: Wed, 06 Feb 2002 18:29:40 +0000
Subject: Re: Auth module security flaw?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4445@lists.php.net to get a copy of this message
On 05 Feb 2002 10:03:47 +0200, Marius Andreiana wrote: >On Du, 2002-02-03 at 11:19, Martin Jansen wrote: >> // {{{ setSessionname() >> >> /** >> * Set name of the session to a customized value. >> * >> * If you are using multiple instances of PEAR Auth >> * on the same domain, you can change the name of >> * session per application via this function. >> * >> * @access public >> * @param string New name for the session >> * @return void >> */ >> function setSessionname($name = "PHPSESSID") >> { >> @session_name($name); >> } >> >> // }}} >> >> What do you think? >It works great. > >But now, what's the point of adding it to Auth class? Consistency :-). Even if the function is a wrapper call for session_name(), we should definitively integrate it in Auth. - Martin -- Martin Jansen, <mail@martin-jansen.de> http://www.martin-jansen.de/

« previous php.pear.dev (#4445) next »