Auth feature
| From: | Yavor Shahpasov | Date: | Sat, 05 Apr 2003 18:38:07 +0000 |
| Subject: | Auth feature | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-14926@lists.php.net to get a copy of this message | ||
http://www.sanisoft.com/phplib/manual/auth_Response.php
i was going other this out of curiosity, it seems phplib supports challenge
responce. I think it would be neat to have this in PEAR auth, it would only
work if the password can be retrieved from the backend so some backends
could not implemend this but I think it should be doable for DB and
File/Passwd
from phplib docs
Example_Challenge_Auth includes crloginform.ihtml. It also requires that
the file md5.js is present in the document root directory of your web
server. That file contains an implementation of the MD5 message digest
algorithm done by Henri Torgemane. The basic idea behind this authentication
scheme is simple: $auth->auth_loginform() creates a challenge value which is
incorporated into this form. When the user tries to submit the form,
MD5("username:password:challenge") is calculated and filled into the reply
field. The password field is erased. The server can calculate the expected
reply from the username received, the password in the database and the
challenge, which it knows. It can compare the expected reply to the actual
reply value. If they match, the user is authenticated.
What do you think, I could probably start working on this, will it be
accepted martin?
Yavor