[pmwiki-users] I want to auth based on pre-existing _SESSION variable with name in it.

Christopher Cox chriscox at endlessnow.com
Sat Sep 26 19:34:11 PDT 2026


On 9/26/26 3:24 AM, Petko Yotov wrote:
> On 26/09/2026 07:56, Christopher Cox wrote:
>> I can make things work using $AuthUserFunctions and my own function.
>> But it requires a form submission.  Is there anyway to make this
>> work if the _SESSION variable containing my id is merely present
>> and somehow obtain correct PmWiki auth based on that?
>> Not interest in hearing about the security of this, I can take care
>> of that later.  I just want to know if this can be done somehow.
> 
> Yes, there is a way, and it can be done somehow.
> 
> The user permissions/groups should be defined in SiteAdmin.AuthUser.
> 
> Something like this, early in config.php:
> 
>    # get the user signed into the other software on the website
>    $session_user = $_SESSION['blog']['username'] ?? '';

I get an error: PHP Warning:  Undefined global variable $_SESSION in 
/var/www/agora/pmwiki/local/config.php on line 56

But I have enabled action diag and it shows $_SESSION and the values inside of 
it.  Am I missing something.  I figured $_SESSION would just be there for use (?).




> 
>    if ( !isset($_POST['authid'])   # not PmWiki authform
>      && empty($_SESSION['authid']) # not already authenticated
>      && !empty($session_user) ) {  # user exists in session
>        $_POST['authid'] = $session_user; # simulate authform post
>        $AuthUserFunctions[$session_user] = 'ccoxAuthSession';
>    }
>    function ccoxAuthSession($pagename, $id) {
>      # do your checks, return true to approve, false to deny
>    }
>    include_once("$FarmD/scripts/authuser.php"); # should come after
> 
> Note that only user id and group based permissions will work. Password-based 
> permissions will not work because no password is posted and PmWiki doesn't store 
> the password.
> 
> So in GroupAttributes?action=attr if you have:
> 
>    @readers @editors id:* id:ccox hashOfPassword123
> 
> ...the password will not work. The user needs to be either in the listed groups, 
> or in the listed ids (but if the user has no permissions, the auth form will 
> reappear so she can type the password).
> 
> Also note that using the link ?action=logout on the wiki may not sign you out: 
> if the session username is still there you will be re-signed in. Similarly if in 
> the other software you sign out, PmWiki may retain the $_SESSION['authid'] value 
> and stay signed in. On PmWiki you can redefine $HandleActions['logout'] to a 
> custom function that also removes the other software's session variables.
> 
> Petko
> 




More information about the pmwiki-users mailing list