[TYPO3-dev] Problem with RSAAuth extension

Helmut Hummel helmut.hummel at typo3.org
Mon Oct 24 15:23:32 CEST 2011


Hi!

Dmitry Dulepov wrote:

> Helmut Hummel wrote:
>> So we accept this breaking change and the preformance problems instead
>> of fixing the session check properly in rsaauth? [1]
>
> I keep my position: that's not a proper check

Sorry if I missed it, but what is a proper check that a php session is 
started from your perspective?
Why do we need this check there anyways, if a second session_start() 
does nothing?

> and not a proper place.

What would be the correct place and why?

> I already explained my reasons and have nothing to add.

Well, it is not clear to me why you want to add a session_start() in the 
beginning of index_ts.php

Kind regards,
Helmut

-- 
Helmut Hummel
TYPO3 Security Team Leader, TYPO3 v4 Core Team Member

TYPO3 .... inspiring people to share!
Get involved: typo3.org



More information about the TYPO3-dev mailing list