cvs: pearweb /include pear-auth.php /public_html login.php
| From: | Richard Heyes | Date: | Fri, 22 Nov 2002 15:56:42 +0000 |
| Subject: | cvs: pearweb /include pear-auth.php /public_html login.php | ||
| Groups: | php.pear.cvs | ||
| Request: | Send a blank email to pear-cvs+get-7531@lists.php.net to get a copy of this message | ||
richard Fri Nov 22 10:56:42 2002 EDT
Modified files:
/pearweb/include pear-auth.php
/pearweb/public_html login.php
Log:
Update crypt()ed passwords to md5()
Any problems this may cause - it's needed to prevent clear text passwords in cookies.
Index: pearweb/include/pear-auth.php
diff -u pearweb/include/pear-auth.php:1.24 pearweb/include/pear-auth.php:1.25
--- pearweb/include/pear-auth.php:1.24 Fri Nov 22 09:55:24 2002
+++ pearweb/include/pear-auth.php Fri Nov 22 10:56:42 2002
@@ -15,7 +15,7 @@
+----------------------------------------------------------------------+
| Authors: |
+----------------------------------------------------------------------+
- $Id: pear-auth.php,v 1.24 2002/11/22 14:55:24 richard Exp $
+ $Id: pear-auth.php,v 1.25 2002/11/22 15:56:42 richard Exp $
*/
function auth_reject($realm = null, $message = null, $refresh = false)
@@ -48,7 +48,7 @@
print " </tr>\n";
print " <tr>\n";
print " <td> </td>\n";
- print " <td><input type=\"checkbox\"
name=\"PEAR_PERSIST\" value=\"on\"> Remember username and
password.</td>\n";
+ print " <td><input type=\"checkbox\"
name=\"PEAR_PERSIST\" value=\"on\" id=\"pear_persist_chckbx\">
<label for=\"pear_persist_chckbx\">Remember username and
password.</label></td>\n";
print " </tr>\n";
print " <tr>\n";
print " <td> </td>\n";
Index: pearweb/public_html/login.php
diff -u pearweb/public_html/login.php:1.11 pearweb/public_html/login.php:1.12
--- pearweb/public_html/login.php:1.11 Fri Nov 22 09:51:17 2002
+++ pearweb/public_html/login.php Fri Nov 22 10:56:42 2002
@@ -15,7 +15,7 @@
+----------------------------------------------------------------------+
| Authors: |
+----------------------------------------------------------------------+
- $Id: login.php,v 1.11 2002/11/22 14:51:17 richard Exp $
+ $Id: login.php,v 1.12 2002/11/22 15:56:42 richard Exp $
*/
if (auth_verify(@$_POST['PEAR_USER'], @$_POST['PEAR_PW'])) {
@@ -26,14 +26,25 @@
}
setcookie('PEAR_USER', $_POST['PEAR_USER'], $expire, '/');
setcookie('PEAR_PW', md5($_POST['PEAR_PW']), $expire, '/');
+
+ /**
+ * Update users password if it is held in the db
+ * crypt()ed.
+ */
+ if (strlen(@$auth_user->password) == 13) { // $auth_user comes from auth_verify() function
+ $dbh->query(sprintf("UPDATE users SET password = '%s' WHERE handle =
'%s'", md5($_POST['PEAR_PW']), $_POST['PEAR_USER']));
+ }
+
+ /**
+ * Determine URL
+ */
if (isset($_POST['PEAR_OLDURL'])) {
$gotourl = $_POST['PEAR_OLDURL'];
} else {
$gotourl = '/';
}
- Header("Refresh: 0; url=$gotourl");
- print "<a href=\"$gotourl\">Click here if your browser does not redirect
you automatically.</a>\n";
- exit;
+
+ localRedirect($gotourl);
}
auth_reject();