Auth Challenge Responce
| From: | Yavor Shahpasov | Date: | Sun, 25 May 2003 01:49:30 +0000 |
| Subject: | Auth Challenge Responce | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-16660@lists.php.net to get a copy of this message | ||
A while back I asked about this in the list, whether it would be feasible to add such a feature in
Auth. I have implemented a proof of consept modification of it. I know it has taken me a while to do
it you can easily blame my lazines impossible deadlines at work, final, the fact I got married this
month or str_replace('%my_excuse%', generateRandomExcuse(), 'this email'). any
how here is a list of things done. Is is a draft by no means it is meant to be the complete thing
!!!
changes made to auth include
Auth.php
*added a Auth::setUseChap(); method, which enable challenge responce (missing is detection of java
script capability on the browser, if not this should throw a warning and use the standard auth
features)
* added an importJS method, this basically includes some java script files it is called by the
drawLogin
+- changed the drawLogin method, if chap is enabled it uses the java script to change the password
to the challenge responce, it allso passes the secret as a hiddent field
* added getChallenge method, this return the server to be used currently it just returns the session
id but it could be easily changed, everything uses this method to get the challeneg secret
Container.php
*added a verifyChap method, similar to
Container/DB.php
*added a fetchChapData, same as fetchLoginData but calls virifyChap instead of verifyPasword, it
also passes different parameters to the virifyChap method than verify password ($challenge,
$challengeresponce,$entry[$this->options['passwordcol']],$chaptemplate)
General structure
if chap is enable, some java script files are included
oncklick event of the submit button replaces the password with the challenge responce string
is chap is enabled and the current container does not have a fetchChap method an die error is thrown
else fetchChap is called instead of fetchData
fetchChap does the same work as fetchData but it verifies a challenge responce string (using
Container::verifyChap method), this is a bit redundant but different data must be passed down the
line (fetchData accepts onl username and fetchChapData accepts username, challenge secret, challenge
responce)
There is something i called a chap template basically it is a template string chich specifies how
the chap should be generated is ie '%challenge%%responce%' or
'1%responce%-%challenge%', the %fields% would be replaced by the appropriate values. This
is merely a consept it has not been implamented
see http://mail.itenasolutions.com/~yavo/auth/index.php
for a demo and
http://mail.itenasolutions.com/~yavo/auth/auth.zip
for the code
Yavor