Re: Auth module security flaw?
| From: | Martin Jansen | Date: | Wed, 06 Feb 2002 18:29:40 +0000 |
| Subject: | Re: Auth module security flaw? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4445@lists.php.net to get a copy of this message | ||
On 05 Feb 2002 10:03:47 +0200, Marius Andreiana wrote:
>On Du, 2002-02-03 at 11:19, Martin Jansen wrote:
>> // {{{ setSessionname()
>>
>> /**
>> * Set name of the session to a customized value.
>> *
>> * If you are using multiple instances of PEAR Auth
>> * on the same domain, you can change the name of
>> * session per application via this function.
>> *
>> * @access public
>> * @param string New name for the session
>> * @return void
>> */
>> function setSessionname($name = "PHPSESSID")
>> {
>> @session_name($name);
>> }
>>
>> // }}}
>>
>> What do you think?
>It works great.
>
>But now, what's the point of adding it to Auth class?
Consistency :-). Even if the function is a wrapper call
for session_name(), we should definitively integrate it
in Auth.
- Martin
--
Martin Jansen, <mail@martin-jansen.de>
http://www.martin-jansen.de/