Re: Auth security - logout deleted user
| From: | Michael Haertl | Date: | Wed, 13 Mar 2002 14:07:47 +0000 |
| Subject: | Re: Auth security - logout deleted user | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4975@lists.php.net to get a copy of this message | ||
Martin Jansen wrote:
Maybe i didn't describe it very well. But just think about some user based website, where you must be able to allow or disallow users to access certain pages. Now if a user logs in and is deleted in the user table he can stay logged in forever, even if you think he can't access a single restricted page because you deleted him - because his session still exists. Yes, you could get around this if you use the idle and expire functionallity in Auth. But maybe i don't want to use that features, because i don't want the other users to always re-login after they expired or idled out. If i think longer about it, i wonder why noone else stumbled across this problem :-) MichaelSince most Auth users may not need that, maybe we could add another config method like Auth->setCheckExistance( $checkexistance=false ) to define wether Auth->getAuth() should again check the db for the existance of that user.I don't think I would ever use such a feature, but that does not have to mean very much yet ;-). I will have a deeper look at this at the weekend.