[turba] Security problem

Jan Schneider jan@horde.org
Mon Nov 18 12:00:58 2002


Zitat von Matthias Mahrholz <Matthias.Mahrholz@URZ.Uni-Magdeburg.DE>:

> I have a first user - Max Mahrholz - account 'mahrholz' at
>     email-server 'sunny.urz.uni-magdeburg.de'.
> 
> I have a second user - Fritz Mahrholz - account 'mahrholz' at
>     email-server 'freenet.de'
> 
> When either user login with
>     Username: mahrholz
>     Password: xxx
>     Server: sunny.urz.uni-magdeburg.de
> resp.
>     Username: mahrholz
>     Password: xxx
>     Server: imap.freenet.de
> 
> to access user Max Mahrholz  a n d  user Fritz Mahrholz
> to the same addressbook resp. options!!!

> $conf['server']['server_list'] = false;
> $conf['server']['change_server'] = true;
> 
> server.php:
> 
> $servers['imap'] = array(

>     'realm' => 'urz.uni-magdeburg.de',
>     'preferred' => ''
> );
> 

This realm isn't appended to the name of the user that logs into
sunny.urz.uni-magdeburg.de? It should.

Anyway if you want to append a realm for a server that the user can enter
himself because you disabled the server list, you need to use the vinfo hook
in conf.php.

Jan.

--
http://www.horde.org - The Horde Project
http://www.ammma.de - discover your knowledge
http://www.tip4all.de - Deine private Tippgemeinschaft


More information about the turba mailing list