https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=17427
--- Comment #9 from Tomás Cohen Arazi <tomasco...@gmail.com> --- (In reply to Martin Renvoize from comment #8) > Comment on attachment 56572 [details] [review] > Bug 17427: Replace CGI::Session with Data::Session > > Review of attachment 56572 [details] [review]: > ----------------------------------------------------------------- > > Generally looks good.. minor question about using ENV though.. not sure > about that part of the change. > > ::: C4/Auth.pm > @@ +1111,4 @@ > > $session->param( 'branchname', $branchname ); > > $session->param( 'flags', $userflags ); > > $session->param( 'emailaddress', $emailaddress ); > > + $session->param( 'ip', $ENV{REMOTE_ADDR} ); > > Did we test this against plack? Can we really rely on ENV for > remote_addr... and in fact.. do we not compare the session ip to the env > remote_addr in places as a security check? $ENV{REMOTE_ADDR} is correctly filled on each request by the ReverseProxy middleware as far as I recall (I debugged plack+ENV several days before making the packages plack integration official). -- You are receiving this mail because: You are watching all bug changes. _______________________________________________ Koha-bugs mailing list Koha-bugs@lists.koha-community.org http://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/