cvs: pearweb /include pear-auth.php /public_html login.php

From: Date: Fri, 22 Nov 2002 15:56:42 +0000
Subject: cvs: pearweb /include pear-auth.php /public_html login.php
Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-7531@lists.php.net to get a copy of this message
richard Fri Nov 22 10:56:42 2002 EDT Modified files: /pearweb/include pear-auth.php /pearweb/public_html login.php Log: Update crypt()ed passwords to md5() Any problems this may cause - it's needed to prevent clear text passwords in cookies. Index: pearweb/include/pear-auth.php diff -u pearweb/include/pear-auth.php:1.24 pearweb/include/pear-auth.php:1.25 --- pearweb/include/pear-auth.php:1.24 Fri Nov 22 09:55:24 2002 +++ pearweb/include/pear-auth.php Fri Nov 22 10:56:42 2002 @@ -15,7 +15,7 @@ +----------------------------------------------------------------------+ | Authors: | +----------------------------------------------------------------------+ - $Id: pear-auth.php,v 1.24 2002/11/22 14:55:24 richard Exp $ + $Id: pear-auth.php,v 1.25 2002/11/22 15:56:42 richard Exp $ */ function auth_reject($realm = null, $message = null, $refresh = false) @@ -48,7 +48,7 @@ print " </tr>\n"; print " <tr>\n"; print " <td>&nbsp;</td>\n"; - print " <td><input type=\"checkbox\" name=\"PEAR_PERSIST\" value=\"on\"> Remember username and password.</td>\n"; + print " <td><input type=\"checkbox\" name=\"PEAR_PERSIST\" value=\"on\" id=\"pear_persist_chckbx\"> <label for=\"pear_persist_chckbx\">Remember username and password.</label></td>\n"; print " </tr>\n"; print " <tr>\n"; print " <td>&nbsp;</td>\n"; Index: pearweb/public_html/login.php diff -u pearweb/public_html/login.php:1.11 pearweb/public_html/login.php:1.12 --- pearweb/public_html/login.php:1.11 Fri Nov 22 09:51:17 2002 +++ pearweb/public_html/login.php Fri Nov 22 10:56:42 2002 @@ -15,7 +15,7 @@ +----------------------------------------------------------------------+ | Authors: | +----------------------------------------------------------------------+ - $Id: login.php,v 1.11 2002/11/22 14:51:17 richard Exp $ + $Id: login.php,v 1.12 2002/11/22 15:56:42 richard Exp $ */ if (auth_verify(@$_POST['PEAR_USER'], @$_POST['PEAR_PW'])) { @@ -26,14 +26,25 @@ } setcookie('PEAR_USER', $_POST['PEAR_USER'], $expire, '/'); setcookie('PEAR_PW', md5($_POST['PEAR_PW']), $expire, '/'); + + /** + * Update users password if it is held in the db + * crypt()ed. + */ + if (strlen(@$auth_user->password) == 13) { // $auth_user comes from auth_verify() function + $dbh->query(sprintf("UPDATE users SET password = '%s' WHERE handle = '%s'", md5($_POST['PEAR_PW']), $_POST['PEAR_USER'])); + } + + /** + * Determine URL + */ if (isset($_POST['PEAR_OLDURL'])) { $gotourl = $_POST['PEAR_OLDURL']; } else { $gotourl = '/'; } - Header("Refresh: 0; url=$gotourl"); - print "<a href=\"$gotourl\">Click here if your browser does not redirect you automatically.</a>\n"; - exit; + + localRedirect($gotourl); } auth_reject();

« previous php.pear.cvs (#7531) next »