[imp] Password disclosure

Jon Parise jon@horde.org
Mon, 26 Nov 2001 19:32:35 -0500


On Mon, Nov 26, 2001 at 10:33:55AM +0000, Lars Hecking wrote:

>  Can someone please point out how do disable either writing the
>  password to the session file or writing the session file altogether?
>  I poked around in horde/lib/Prefs.php, but couldn't really make much
>  sense of it.

It has nothing to do with the preferences.

The password is being stored as part of the authentication
credentials, which are also stored in the session.

-- 
Jon Parise (jon@csh.rit.edu)  .  Information Technology (2001)
http://www.csh.rit.edu/~jon/  :  Computer Science House Member