[pmwiki-users] I want to auth based on pre-existing _SESSION variable with name in it.

Petko Yotov 5ko at 5ko.fr
Sat Sep 26 01:24:31 PDT 2026


On 26/09/2026 07:56, Christopher Cox wrote:
> I can make things work using $AuthUserFunctions and my own function.
> But it requires a form submission.  Is there anyway to make this
> work if the _SESSION variable containing my id is merely present
> and somehow obtain correct PmWiki auth based on that?
> Not interest in hearing about the security of this, I can take care
> of that later.  I just want to know if this can be done somehow.

Yes, there is a way, and it can be done somehow.

The user permissions/groups should be defined in SiteAdmin.AuthUser.

Something like this, early in config.php:

   # get the user signed into the other software on the website
   $session_user = $_SESSION['blog']['username'] ?? '';

   if ( !isset($_POST['authid'])   # not PmWiki authform
     && empty($_SESSION['authid']) # not already authenticated
     && !empty($session_user) ) {  # user exists in session
       $_POST['authid'] = $session_user; # simulate authform post
       $AuthUserFunctions[$session_user] = 'ccoxAuthSession';
   }
   function ccoxAuthSession($pagename, $id) {
     # do your checks, return true to approve, false to deny
   }
   include_once("$FarmD/scripts/authuser.php"); # should come after

Note that only user id and group based permissions will work. 
Password-based permissions will not work because no password is posted 
and PmWiki doesn't store the password.

So in GroupAttributes?action=attr if you have:

   @readers @editors id:* id:ccox hashOfPassword123

...the password will not work. The user needs to be either in the listed 
groups, or in the listed ids (but if the user has no permissions, the 
auth form will reappear so she can type the password).

Also note that using the link ?action=logout on the wiki may not sign 
you out: if the session username is still there you will be re-signed 
in. Similarly if in the other software you sign out, PmWiki may retain 
the $_SESSION['authid'] value and stay signed in. On PmWiki you can 
redefine $HandleActions['logout'] to a custom function that also removes 
the other software's session variables.

Petko

-- 
If you upgrade :  https://www.pmwiki.org/Upgrades



More information about the pmwiki-users mailing list