Duplicated/redundant package for PEAR::Message -> PEAR::Crypt_HMAC - was Re: [PEAR-DEV] Package Proposal: Auth_HMAC
| From: | Jesus M. Castagnetto | Date: | Thu, 24 Apr 2003 18:02:43 +0000 |
| Subject: | Duplicated/redundant package for PEAR::Message -> PEAR::Crypt_HMAC - was Re: [PEAR-DEV] Package Proposal: Auth_HMAC | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-15479@lists.php.net to get a copy of this message | ||
Davey just reminded me again something I asked here before and for which I did
not get definitive answers.
When was Crypt_HMAC proposed/approved? I do not seem to find it in the pear-dev
archives.
PEAR::Crypt_HMAC is (IMHO) a redundant package, as its functionality was
already available in PEAR::Message (via the fallback classes).
Looking at the CVS logs, Crypt_HMAC was commited on February 16, 2003;
meanwhile, the original commit for Message was October 1, 2002, and the last
release including the fallback (no mhash needed) classes was on November 26,
2002.
My questions are:
1) What do we do when there are newer packages that implement existing
functionality from an older package?
2) When was Crypt_HMAC proposed/approved? I searched MARC and had no luck (see:
http://marc.theaimsgroup.com/?l=pear-dev&w=2&r=1&s=Crypt_HMAC&q=b)
3) How do we resolve when a new package is released and is in contention with
the functionality of an older one? Do we remove it? Do we deprecate it?
BTW, when I was proposing PEAR::Message back in September 2002, I originally
named 'Digest' but that did not seem to clear at least to one person who
responded, so I use 'Message' and that seemed to be OK then.
Here are the search results at MARC:
http://marc.theaimsgroup.com/?l=pear-dev&w=2&r=1&s=hmac&q=b
Comments/pointers/rants/more info?
--- Davey <davey@pixelated-dreams.com> wrote:
> Well, brave words as they may be, I'm hoping it'll get a) some rigourous
> testing and b) proven
>
> I have had the code reviewed by serveral people I (and many others)
> believe to be well endowed with PHP knowledge, and all have said the
> code looks decent, so we'll see :D
>
> As I said, I will release the code soon, I have also noticed the
> Crypt_HMAC package, so I'll use that if anything pre-existing in PEAR
> (if its compatible :)
>
> - Davey
>
> Martin Jansen wrote:
> > On Thu Apr 24, 2003 at 01:5226PM +0100, Davey wrote:
> >
> >>OK, I've been working on a new login system for my CMS these last few
> >>weeks, and I now believe I have *the* strongest non-SSL login ever.
> >
> >
> > Brave words. But honestly, if I were you, I wouldn't proclaim them too
> > loud ;-).
> >
> >
> >>basically, *every* time the login form is generate, a random hash is
> >>generated (currently $hash = md5(uniqid(nt_rand(),1));), this is split
> >>into two halves and stored in $_SESSION.
> >
> >
> > May we see the code?
=====
--- Jesus M. Castagnetto (jcastagnetto@yahoo.com)
Research:
http://metallo.scripps.edu/
Personal: http://www.castagnetto.org/
__________________________________________________
Do you Yahoo!?
The New Yahoo! Search - Faster. Easier. Bingo
http://search.yahoo.com