cvs: pearweb /include pear-auth.php
| From: | Richard Heyes | Date: | Fri, 22 Nov 2002 14:55:24 +0000 |
| Subject: | cvs: pearweb /include pear-auth.php | ||
| Groups: | php.pear.cvs | ||
| Request: | Send a blank email to pear-cvs+get-7530@lists.php.net to get a copy of this message | ||
richard Fri Nov 22 09:55:24 2002 EDT
Modified files:
/pearweb/include pear-auth.php
Log:
Fix authentication to handle md5()ed cookies
Index: pearweb/include/pear-auth.php
diff -u pearweb/include/pear-auth.php:1.23 pearweb/include/pear-auth.php:1.24
--- pearweb/include/pear-auth.php:1.23 Sun Jun 9 19:05:53 2002
+++ pearweb/include/pear-auth.php Fri Nov 22 09:55:24 2002
@@ -15,7 +15,7 @@
+----------------------------------------------------------------------+
| Authors: |
+----------------------------------------------------------------------+
- $Id: pear-auth.php,v 1.23 2002/06/09 23:05:53 richard Exp $
+ $Id: pear-auth.php,v 1.24 2002/11/22 14:55:24 richard Exp $
*/
function auth_reject($realm = null, $message = null, $refresh = false)
@@ -93,7 +93,13 @@
}
// handle new-style MD5-encrypted passwords
case 32: {
- $crypted = md5($passwd);
+ // Check if the passwd is already md5()ed
+ if (preg_match('/^[a-z0-9]{32}$/', $passwd)) {
+ $crypted = $passwd;
+ } else {
+ $crypted = md5($passwd);
+ }
+
if ($crypted == @$auth_user->password) {
$ok = true;
} else {