Auth security - logout deleted user
| From: | Michael Haertl | Date: | Wed, 13 Mar 2002 12:33:36 +0000 |
| Subject: | Auth security - logout deleted user | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-4972@lists.php.net to get a copy of this message | ||
Hi,
i've found another little problem with Auth:
If a user is deleted from the database while being logged in to the
website, Auth->getAuth() still returns "true" for this user, even he
doesn't exist any longer. The reason for this is, that the
authentication state is saved in the $auth session var.
That behaviour may be o.k. since AFAIK on Linux it would be the same
if you delete a user from /etc/passwd while being logged in. In that
case the user can stay logged in until he logs out.
But i've got a case where exactly this behaviour is problematic.
So to prevent this, Auth->getAuth() would have to look for the user
in the db everytime it get's called.
Since most Auth users may not need that, maybe we could add another
config method like Auth->setCheckExistance( $checkexistance=false )
to define wether Auth->getAuth() should again check the db for the
existance of that user.
If that makes sense to someone i would implement it and send the diffs.
Michael