Re: Auth_HTTP glaring security hole
| From: | Alan Knowles | Date: | Mon, 06 May 2002 23:05:42 +0000 |
| Subject: | Re: Auth_HTTP glaring security hole | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-5987@lists.php.net to get a copy of this message | ||
For technical reasons browsers dont support logging out of HTTP authentication, its a problem with the underlying HTTP standard - there isnt much you can do ....
if you do need logout, and need it to work pretty much on all browsers (without cookies), look at trans_sess id's and sessions.
the use of http authentication is really useful for 'low level secure areas', or for http RPC calls
regards
alan
Ross Smith II wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Either I'm just dense, or Auth_HTTP has a huge security hole. When I use Auth_HTTP and attempt to logout via: $a->logout(); $a->start(); I'm not presented with the login dialog. So I tried: $a->logout(); $a->drawLogin(); Now I get the login dialog, but I'm able to subvert this, by simply selecting Cancel, then clicking the back button in my browser until the "logged in" page is displayed. Any ideas on how to really logout in Auth_HTTP? After spending several hours try to come up with a patch, the only way I've found to truly "logout" is to close the browser window. Should I give up Auth_HTTP and just use Auth? For technical reasons, I would prefer to use Auth_HTTP. Thanks, Ross -----BEGIN PGP SIGNATURE----- Version: 6.5.8ckt http://www.ipgpp.com/ Comment: KeyID: 0xADAD77FB Comment: Fingerprint: F54F FB60 33FF 1582 977C 8E3F A4DE 95E1 ADAD 77FB iQA/AwUBPNa/laTeleGtrXf7EQIfdACbBRMWEUv8AgU1nK6h4ObWDTO7Q/YAn3uF R2ZdpxC4AcwE2Xiu414HnnHY =hH1r -----END PGP SIGNATURE-----