[pmwiki-users] I want to auth based on pre-existing _SESSION variable with name in it.
Christopher Cox
chriscox at endlessnow.com
Sat Sep 26 19:34:11 PDT 2026
On 9/26/26 3:24 AM, Petko Yotov wrote:
> On 26/09/2026 07:56, Christopher Cox wrote:
>> I can make things work using $AuthUserFunctions and my own function.
>> But it requires a form submission. Is there anyway to make this
>> work if the _SESSION variable containing my id is merely present
>> and somehow obtain correct PmWiki auth based on that?
>> Not interest in hearing about the security of this, I can take care
>> of that later. I just want to know if this can be done somehow.
>
> Yes, there is a way, and it can be done somehow.
>
> The user permissions/groups should be defined in SiteAdmin.AuthUser.
>
> Something like this, early in config.php:
>
> # get the user signed into the other software on the website
> $session_user = $_SESSION['blog']['username'] ?? '';
I get an error: PHP Warning: Undefined global variable $_SESSION in
/var/www/agora/pmwiki/local/config.php on line 56
But I have enabled action diag and it shows $_SESSION and the values inside of
it. Am I missing something. I figured $_SESSION would just be there for use (?).
>
> if ( !isset($_POST['authid']) # not PmWiki authform
> && empty($_SESSION['authid']) # not already authenticated
> && !empty($session_user) ) { # user exists in session
> $_POST['authid'] = $session_user; # simulate authform post
> $AuthUserFunctions[$session_user] = 'ccoxAuthSession';
> }
> function ccoxAuthSession($pagename, $id) {
> # do your checks, return true to approve, false to deny
> }
> include_once("$FarmD/scripts/authuser.php"); # should come after
>
> Note that only user id and group based permissions will work. Password-based
> permissions will not work because no password is posted and PmWiki doesn't store
> the password.
>
> So in GroupAttributes?action=attr if you have:
>
> @readers @editors id:* id:ccox hashOfPassword123
>
> ...the password will not work. The user needs to be either in the listed groups,
> or in the listed ids (but if the user has no permissions, the auth form will
> reappear so she can type the password).
>
> Also note that using the link ?action=logout on the wiki may not sign you out:
> if the session username is still there you will be re-signed in. Similarly if in
> the other software you sign out, PmWiki may retain the $_SESSION['authid'] value
> and stay signed in. On PmWiki you can redefine $HandleActions['logout'] to a
> custom function that also removes the other software's session variables.
>
> Petko
>
More information about the pmwiki-users
mailing list