Re: Re: cvs: pearweb /public_html login.php

From: Date: Sun, 24 Nov 2002 17:41:23 +0000
Subject: Re: Re: cvs: pearweb /public_html login.php
References: 1 2 3 4 5 6  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-11063@lists.php.net to get a copy of this message
On Sun, Nov 24, 2002 at 12:07:45PM -0000, Richard Heyes wrote: > > > Been thinking about this. It would be even more secure if we could hash > with > > > two secrets, ie the password and some other secret. Problem is, with > pearweb > > > being open to the public this isn't really feasible, unless we use an > > > encoded function to do the hashing. I can supply the encoded function, > if we > > > can get the Optimizer installed on pearweb. > > > > > > How does this sound ? > > > > it would be much simpler to read a file stored outside of the web tree > > to get the server's secret, and that's less likely to break when someone > > upgrades php on that machine. > > Kinda screws up portability though, since if it's not in cvs, it will have > to be retrieved separately by devs. devs shouldn't need the server secret. it wouldn't be a secret then. :) (and requiring the optimizer is likely to be more inconvenient for devs, who are more likely to be running between-releases versions of php.) jim

« previous php.pear.dev (#11063) next »