Auth feature

From: Date: Sat, 05 Apr 2003 18:38:07 +0000
Subject: Auth feature
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-14926@lists.php.net to get a copy of this message
http://www.sanisoft.com/phplib/manual/auth_Response.php i was going other this out of curiosity, it seems phplib supports challenge responce. I think it would be neat to have this in PEAR auth, it would only work if the password can be retrieved from the backend so some backends could not implemend this but I think it should be doable for DB and File/Passwd from phplib docs Example_Challenge_Auth includes crloginform.ihtml. It also requires that the file md5.js is present in the document root directory of your web server. That file contains an implementation of the MD5 message digest algorithm done by Henri Torgemane. The basic idea behind this authentication scheme is simple: $auth->auth_loginform() creates a challenge value which is incorporated into this form. When the user tries to submit the form, MD5("username:password:challenge") is calculated and filled into the reply field. The password field is erased. The server can calculate the expected reply from the username received, the password in the database and the challenge, which it knows. It can compare the expected reply to the actual reply value. If they match, the user is authenticated. What do you think, I could probably start working on this, will it be accepted martin? Yavor

« previous php.pear.dev (#14926) next »