Auth security - logout deleted user

From: Date: Wed, 13 Mar 2002 12:33:36 +0000
Subject: Auth security - logout deleted user
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4972@lists.php.net to get a copy of this message
Hi, i've found another little problem with Auth: If a user is deleted from the database while being logged in to the website, Auth->getAuth() still returns "true" for this user, even he doesn't exist any longer. The reason for this is, that the authentication state is saved in the $auth session var. That behaviour may be o.k. since AFAIK on Linux it would be the same if you delete a user from /etc/passwd while being logged in. In that case the user can stay logged in until he logs out. But i've got a case where exactly this behaviour is problematic. So to prevent this, Auth->getAuth() would have to look for the user in the db everytime it get's called. Since most Auth users may not need that, maybe we could add another config method like Auth->setCheckExistance( $checkexistance=false ) to define wether Auth->getAuth() should again check the db for the existance of that user. If that makes sense to someone i would implement it and send the diffs. Michael

« previous php.pear.dev (#4972) next »