Re: Auth_HMAC problems

From: Date: Sun, 04 May 2003 17:09:25 +0000
Subject: Re: Auth_HMAC problems
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-15834@lists.php.net to get a copy of this message
Davey wrote:
OK, so there I am recoding Auth_HMAC from scratch. I've now reached a dead end. I have 2 problems: 1) kills apache process with PHP 4.2.2 on windows 2) throws an error on PHP 4.3.1 (FBSD) and 4.3.2RC2 (win32) The error follows: Fatal error: ob_start(): No method name given: use ob_start(array($object,'method')) to specify instance $object and the name of a method of class auth_hmac to use as output handler in C:\php4\pear\Auth\HMAC.php on line 68 This is line 68: ob_start(array(&$this,'requireAuth',$level,$show_form)); I think its pretty obvious what I'm trying to do... the package can be gotten from http://www.pixelated-dreams.com/~davey/PEAR/release/Auth_HMAC-0.8.tgz It includes an example script and all JS and such thats needed. The example script includes a MySQL (although will probably work on PgSQL et al; without too much jiggery pokery) dump in the comments at the top of it. You will need to edit the example, provide a valid DSN and change the values in the $table array. I would appreciate everyone looking at this code to see what they think of the concept, in how it works and such, and whether or not you want it in PEAR (once its bugs are ironed out) Just an update on how this works: * evern login request it generates a MD5 or SHA1 hash, this is the key for our HMAC, its stored in $_SESSION['hash']
s/evern/every/
* then it outputs the neccessary JS so that when the user clicks login it HMAC's the input username+password using the PHP generated key, and it then sends the HMAC result hash and plaintext password to the script.
s/plaintext password/plaintext username/
* Using MDB a SELECT password,level FROM table WHERE username='$_POST['username'] is done * HMAC is performed again using the supplied username, the $_SESSION['hash'] and the password from the DB. * then an if ($_POST['hash'] == $serverside_hmac) is performed, is this returns TRUE we know two things, the source of the data can be trusted (keys match) and the username/password given were correct (same data is input from client and fetch from DB) * there ARE non-JS fallbacks, when the form is first output, its setup for non-JS browsers, JS then changes the form before sending, and PHP can tell whether or not it has been used. * because $_SESSION['hash'] is sent in the form HTML (<input type="hidden">) we can check that this matches the $_SESSION['hash'] and then we can do an if ($_POST['password'] == $db['password']) - whilst not being anywhere near secure, we still do some source integrity checking. I am thinking of including a purely 'eyecandy' piece of code which will output the neccessary JS+HTML to automatically say if the user is using Standard login mode versus Secure login mode. I'm also going to write in SSL checking, so that the user can force their visitors to only view the data through SSL. This *should* be setup in the httpd config, but quite often (in my experience) is not and therefore needs to be solved programmatically. Sorry for the huge long e-mail, but I felt it neccessary to fully explain Auth_HMAC and hopefully you guys will be able to help me and also accept the package. - Davey
sorry about those mistakes I wrote it just before I fell asleep. now, how about some replies? :D - Davey

« previous php.pear.dev (#15834) next »