[Tickets #8531] Configuration doesn't warn about non-alphanumerics in session name.
bugs at horde.org
bugs at horde.org
Thu Aug 27 06:56:59 UTC 2009
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.
Ticket URL: http://bugs.horde.org/ticket/8531
------------------------------------------------------------------------------
Ticket | 8531
Created By | rpjday at crashcourse.ca
Summary | Configuration doesn't warn about non-alphanumerics in
| session name.
Queue | Horde Base
Version | 3.3.4
Type | Bug
State | Unconfirmed
Priority | 1. Low
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------
rpjday at crashcourse.ca (2009-08-27 06:56) wrote:
Apparently, when configuring a 3.3.4 Horde install, using a session
name of "Horde-3.3.4" causes problems with PHP (because of
non-alphanumerics in the session name), which then causes all attempts
to log in to be quietly verified, then dropped. There is no apparent
warning that this is happening, and no apparent subsequent diagnostics
during those failed login attempts.
It might be useful for the configuration to either warn the user about
non-alphanumerics in the session name, or just reject such names
outright.
Switching to the session name of "Horde334" caused logins to start
working again.
More information about the bugs
mailing list