[Tickets #8531] Configuration doesn't warn about non-alphanumerics in session name.

bugs at horde.org bugs at horde.org
Thu Aug 27 06:56:59 UTC 2009


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/8531
------------------------------------------------------------------------------
  Ticket             | 8531
  Created By         | rpjday at crashcourse.ca
  Summary            | Configuration doesn't warn about non-alphanumerics in
                     | session name.
  Queue              | Horde Base
  Version            | 3.3.4
  Type               | Bug
  State              | Unconfirmed
  Priority           | 1. Low
  Milestone          |
  Patch              |
  Owners             |
------------------------------------------------------------------------------


rpjday at crashcourse.ca (2009-08-27 06:56) wrote:

Apparently, when configuring a 3.3.4 Horde install, using a session  
name of "Horde-3.3.4" causes problems with PHP (because of  
non-alphanumerics in the session name), which then causes all attempts  
to log in to be quietly verified, then dropped.  There is no apparent  
warning that this is happening, and no apparent subsequent diagnostics  
during those failed login attempts.

It might be useful for the configuration to either warn the user about  
non-alphanumerics in the session name, or just reject such names  
outright.

Switching to the session name of "Horde334" caused logins to start  
working again.







More information about the bugs mailing list