Duplicated/redundant package for PEAR::Message -> PEAR::Crypt_HMAC - was Re: [PEAR-DEV] Package Proposal: Auth_HMAC

From: Date: Thu, 24 Apr 2003 18:02:43 +0000
Subject: Duplicated/redundant package for PEAR::Message -> PEAR::Crypt_HMAC - was Re: [PEAR-DEV] Package Proposal: Auth_HMAC
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-15479@lists.php.net to get a copy of this message
Davey just reminded me again something I asked here before and for which I did not get definitive answers. When was Crypt_HMAC proposed/approved? I do not seem to find it in the pear-dev archives. PEAR::Crypt_HMAC is (IMHO) a redundant package, as its functionality was already available in PEAR::Message (via the fallback classes). Looking at the CVS logs, Crypt_HMAC was commited on February 16, 2003; meanwhile, the original commit for Message was October 1, 2002, and the last release including the fallback (no mhash needed) classes was on November 26, 2002. My questions are: 1) What do we do when there are newer packages that implement existing functionality from an older package? 2) When was Crypt_HMAC proposed/approved? I searched MARC and had no luck (see: http://marc.theaimsgroup.com/?l=pear-dev&w=2&r=1&s=Crypt_HMAC&q=b) 3) How do we resolve when a new package is released and is in contention with the functionality of an older one? Do we remove it? Do we deprecate it? BTW, when I was proposing PEAR::Message back in September 2002, I originally named 'Digest' but that did not seem to clear at least to one person who responded, so I use 'Message' and that seemed to be OK then. Here are the search results at MARC: http://marc.theaimsgroup.com/?l=pear-dev&w=2&r=1&s=hmac&q=b Comments/pointers/rants/more info? --- Davey <davey@pixelated-dreams.com> wrote: > Well, brave words as they may be, I'm hoping it'll get a) some rigourous > testing and b) proven > > I have had the code reviewed by serveral people I (and many others) > believe to be well endowed with PHP knowledge, and all have said the > code looks decent, so we'll see :D > > As I said, I will release the code soon, I have also noticed the > Crypt_HMAC package, so I'll use that if anything pre-existing in PEAR > (if its compatible :) > > - Davey > > Martin Jansen wrote: > > On Thu Apr 24, 2003 at 01:5226PM +0100, Davey wrote: > > > >>OK, I've been working on a new login system for my CMS these last few > >>weeks, and I now believe I have *the* strongest non-SSL login ever. > > > > > > Brave words. But honestly, if I were you, I wouldn't proclaim them too > > loud ;-). > > > > > >>basically, *every* time the login form is generate, a random hash is > >>generated (currently $hash = md5(uniqid(nt_rand(),1));), this is split > >>into two halves and stored in $_SESSION. > > > > > > May we see the code? ===== --- Jesus M. Castagnetto (jcastagnetto@yahoo.com) Research: http://metallo.scripps.edu/ Personal: http://www.castagnetto.org/ __________________________________________________ Do you Yahoo!? The New Yahoo! Search - Faster. Easier. Bingo http://search.yahoo.com

« previous php.pear.dev (#15479) next »