cvs: pear /Auth/Auth Controller.php /Auth/Container DB.php

From: Date: Sun, 04 Jul 2004 21:21:04 +0000
Subject: cvs: pear /Auth/Auth Controller.php /Auth/Container DB.php
Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-21508@lists.php.net to get a copy of this message
yavo Sun Jul 4 17:21:04 2004 EDT Modified files: /pear/Auth/Auth Controller.php /pear/Auth/Container DB.php Log: Some code corrections http://cvs.php.net/diff.php/pear/Auth/Auth/Controller.php?r1=1.6&r2=1.7&ty=u Index: pear/Auth/Auth/Controller.php diff -u pear/Auth/Auth/Controller.php:1.6 pear/Auth/Auth/Controller.php:1.7 --- pear/Auth/Auth/Controller.php:1.6 Sun Jul 4 13:59:36 2004 +++ pear/Auth/Auth/Controller.php Sun Jul 4 17:21:04 2004 @@ -142,6 +142,7 @@ function start() { // Check the accessList here // ACL should be a list of urls with allow/deny + // If allow set allowLogin to false // Some wild card matching should be implemented ?,* if(!strstr($_SERVER['PHP_SELF'], $this->_loginPage) && !$this->auth->checkAuth()) { $this->redirectLogin(); @@ -149,8 +150,6 @@ $this->auth->start(); // Logged on and on login page if(strstr($_SERVER['PHP_SELF'], $this->_loginPage) && $this->auth->checkAuth()){ - // Should we call this here - // or in the login page manually $this->autoRedirectBack ? $this->redirectBack() : null ; http://cvs.php.net/diff.php/pear/Auth/Container/DB.php?r1=1.45&r2=1.46&ty=u Index: pear/Auth/Container/DB.php diff -u pear/Auth/Container/DB.php:1.45 pear/Auth/Container/DB.php:1.46 --- pear/Auth/Container/DB.php:1.45 Sun Jul 4 12:52:20 2004 +++ pear/Auth/Container/DB.php Sun Jul 4 17:21:04 2004 @@ -16,7 +16,7 @@ // | Authors: Martin Jansen <mj@php.net> | // +----------------------------------------------------------------------+ // -// $Id: DB.php,v 1.45 2004/07/04 16:52:20 yavo Exp $ +// $Id: DB.php,v 1.46 2004/07/04 21:21:04 yavo Exp $ // require_once 'Auth/Container.php'; @@ -30,7 +30,7 @@ * * @author Martin Jansen <mj@php.net> * @package Auth - * @version $Revision: 1.45 $ + * @version $Revision: 1.46 $ */ class Auth_Container_DB extends Auth_Container { @@ -113,9 +113,6 @@ } } - // }}} - // {{{ _prepare() - /** * Prepare database connection * @@ -160,9 +157,6 @@ return $this->db->query($query); } - // }}} - // {{{ _setDefaults() - /** * Set some default options * @@ -180,9 +174,6 @@ $this->options['db_options'] = array(); } - // }}} - // {{{ _parseOptions() - /** * Parse options passed to the container class * @@ -217,7 +208,7 @@ * * @param string Username * @param string Password - * @param boolean If true password is secured using an md5 hash + * @param boolean If true password is secured using a md5 hash * the frontend and auth are responsible for making sure the container supports * challenge responce password authenthication * @return mixed Error object or boolean @@ -230,7 +221,7 @@ return PEAR::raiseError($err->getMessage(), $err->getCode()); } - // Find if db_fields contains a *, if so assume all col are selected + // Find if db_fields contains a *, if so assume all columns are selected if (strstr($this->options['db_fields'], '*')) { $sql_from = "*"; } @@ -271,13 +262,11 @@ // Perform trimming here before the hashihg $password = trim($password, "\r\n"); $res[$this->options['passwordcol']] = trim($res[$this->options['passwordcol']], "\r\n"); - // If using Challeneg Responce md5 the pass with the secret - if($isChallengeResponce) { - //print " Orig Password [{$res[$this->options['passwordcol']]}]<br/>\n"; - //print " Challenge [{$this->_auth_obj->session['loginchallenege']}]<br/>\n"; + // If using Challenge Responce md5 the pass with the secret + if ($isChallengeResponce) { $res[$this->options['passwordcol']] = md5($res[$this->options['passwordcol']].$this->_auth_obj->session['loginchallenege']); // UGLY cannot avoid without modifying verifyPassword - if($this->options['cryptType'] == 'md5') { + if ($this->options['cryptType'] == 'md5') { $res[$this->options['passwordcol']] = md5($res[$this->options['passwordcol']]); } //print " Hashed Password [{$res[$this->options['passwordcol']]}]<br/>\n"; @@ -293,23 +282,20 @@ } // Use reference to the auth object if exists // This is because the auth session variable can change so a static call to setAuthData does not make sence - if (is_object($this->_auth_obj)) { - $this->_auth_obj->setAuthData($key, $value); - } else { - Auth::setAuthData($key, $value); - } + $this->_auth_obj->setAuthData($key, $value); } - return true; } - $this->activeUser = $res[$this->options['usernamecol']]; return false; } - // }}} - // {{{ listUsers() - + /** + * Returns a list of users from the container + * + * @return mixed + * @access public + */ function listUsers() { $err = $this->_prepare(); @@ -322,8 +308,7 @@ // Find if db_fields contains a *, if so assume all col are selected if (strstr($this->options['db_fields'], '*')) { $sql_from = "*"; - } - else{ + } else { $sql_from = $this->options['usernamecol'] . ", ".$this->options['passwordcol'].$this->options['db_fields']; } @@ -344,9 +329,6 @@ return $retVal; } - // }}} - // {{{ addUser() - /** * Add user to the storage container * @@ -398,9 +380,6 @@ } } - // }}} - // {{{ removeUser() - /** * Remove user from the storage container * @@ -426,9 +405,6 @@ } } - // }}} - // {{{ changePassword() - /** * Change password for user in the storage container * @@ -464,17 +440,26 @@ } } + /** + * Determine if this container supports + * password authenthication with challenge responce + * + * @return bool + * @access public + */ function supportsChallengeResponce() { - if( $this->options['cryptType'] == 'md5' || $this->options['cryptType'] == 'none' || $this->options['cryptType'] == '' ) { + if( in_array($this->options['cryptType'], array('md5', 'none', '') ) { return(true); } return(false); } + /** + * Returns the selected crypt type for this container + */ function getCryptType() { return($this->options['cryptType']); } - // }}} } ?>

« previous php.pear.cvs (#21508) next »