Menu

#73 SM 1.4.3a: incompatibility with Webmin (cookie user)

open
None
5
2004-12-27
2004-08-04
No

Webmin and Squirrelmail use a cookie named user. So if
a user is using Webmin and Squirrelmail who are twice
installed on the same host, login page of squirrelmail
will not work as espected.

I suggest to change cookie's name to sqm_user.

Discussion

  • Florent Guiliani

    Logged In: YES
    user_id=9879

    WebCalendar also use a cookie named user. So there is an
    incompatbility bitween Webmin, Squirrelmail and Webcalendar.

     
  • Jonathan Angliss

    • assigned_to: nobody --> jangliss
    • status: open --> pending
     
  • Jonathan Angliss

    Logged In: YES
    user_id=620333

    Incorrect statement. SquirrelMail itself doesn't use a
    cookie named user. The only cookie SquirrelMail itself sets
    is one called KEY. Their is a plugin (login_auto I believe)
    that sets a cookie named "user". Please verify, and make
    sure that this is the case in your setup (ie, you have that
    plugin installed). I know of no core code that sets the
    cookie "user".

     
  • Florent Guiliani

    Logged In: YES
    user_id=9879

    That's it. I've the login auto plugin installed and cookies
    is setup from it.
    I've sent a email to JayGuerette =-at-= pobox and pdontthink
    "#at#" angrynerds to notify this.

     
  • Florent Guiliani

    • status: pending --> open
     
  • Jonathan Angliss

    Logged In: YES
    user_id=620333

    It could be made configurable.

    Re-assigning to Paul if he still manages it.

     
  • Jonathan Angliss

    • labels: --> 477103
    • assigned_to: jangliss --> pdontthink
     
  • Thijs Kinkhorst

    Thijs Kinkhorst - 2004-08-16

    Logged In: YES
    user_id=285765

    But still. isn't 'KEY' a bit too generic? Maybe it doesn't
    cause any problem in this case, but it'd be better to change
    it to SQM_KEY or maybe even better: the configurable
    <session_name> with "_KEY" appended?

     
  • Jonathan Angliss

    Logged In: YES
    user_id=620333

    That might be an idea, but not top priority. I've not seen
    any conflicts, or heard of any yet. It's only been with the
    PHPSESSID cookies that have had issues, which was why I put
    in the session name stuff.

     
  • Thijs Kinkhorst

    Thijs Kinkhorst - 2004-12-27

    Logged In: YES
    user_id=285765

    To summarize, the original report is not a bug in
    SquirrelMail (but in a specific plugin). However there's a
    feature request to change the KEY cookie to something less
    generic. Reported feature request as #1091688, moving this
    to the Plugins tracker.

     
  • Thijs Kinkhorst

    Thijs Kinkhorst - 2004-12-27
    • labels: 477103 -->
     

Log in to post a comment.