Beefy Boxes and Bandwidth Generously Provided by pair Networks
Syntactic Confectionery Delight

Re: ENV{'REMOTE_USER'} is it safe?

by MarkM (Curate)
on Sep 28, 2003 at 18:57 UTC ( #294785=note: print w/replies, xml ) Need Help??

in reply to ENV{'REMOTE_USER'} is it safe?

REMOTE_USER should be safe to use under Apache and most other HTTP servers. The variables that are not safe to use, are the ones that are provided directly from the client. These usually begin with HTTP_*.

Replies are listed 'Best First'.
Re: Re: ENV{'REMOTE_USER'} is it safe?
by spacey (Scribe) on Sep 28, 2003 at 19:25 UTC
    Thanks for the clarification
    I was concerned that a user who may have already authenticated would be able to push a modified REMOTE_USER variable.
      In theory they can. Because HTTP is stateless, the username and password have to be supplied again for each request. Users don't see this because the browser handles it for them. In practice they can't, because most (all?) browsers don't give the user an easy way to change their username and password once they have successfully logged in to your site, but some might, and if they are using their own program or talking raw HTTP at your server or something similar then all bets are off.

      Even so, if the user *can* send some other username/password, that username/password would still have to be accepted by your web server before they could get at any content so it's probably not something you need to worry about.

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://294785]
[Corion]: Discipulus: Yeah, from my investigations, you can somewhat silence+disable Cortana, but some services of it remain always running unfortunately. What a waste of resources :-/
[Corion]: I hope you had a good weekend still ;)
choroba had a workshop with the band
[choroba]: which counts as a good weekend
[Discipulus]: yes, (at least until Sun afternoon...): Saturday we got splendid birthday party in a park: lot of eat, drink and children amusement: bag running, magnetic fishing, rope and that big pot full of candies to smash with a club

How do I use this? | Other CB clients
Other Users?
Others pondering the Monastery: (6)
As of 2017-09-25 08:35 GMT
Find Nodes?
    Voting Booth?
    During the recent solar eclipse, I:

    Results (277 votes). Check out past polls.