Re: Auth security - logout deleted user

From: Date: Wed, 13 Mar 2002 14:07:47 +0000
Subject: Re: Auth security - logout deleted user
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4975@lists.php.net to get a copy of this message
Martin Jansen wrote:
Since most Auth users may not need that, maybe we could add another config method like Auth->setCheckExistance( $checkexistance=false ) to define wether Auth->getAuth() should again check the db for the existance of that user.
I don't think I would ever use such a feature, but that does not have to mean very much yet ;-). I will have a deeper look at this at the weekend.
Maybe i didn't describe it very well. But just think about some user based website, where you must be able to allow or disallow users to access certain pages. Now if a user logs in and is deleted in the user table he can stay logged in forever, even if you think he can't access a single restricted page because you deleted him - because his session still exists. Yes, you could get around this if you use the idle and expire functionallity in Auth. But maybe i don't want to use that features, because i don't want the other users to always re-login after they expired or idled out. If i think longer about it, i wonder why noone else stumbled across this problem :-) Michael

« previous php.pear.dev (#4975) next »