Auth Challenge Responce

From: Date: Sun, 25 May 2003 01:49:30 +0000
Subject: Auth Challenge Responce
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-16660@lists.php.net to get a copy of this message
A while back I asked about this in the list, whether it would be feasible to add such a feature in Auth. I have implemented a proof of consept modification of it. I know it has taken me a while to do it you can easily blame my lazines impossible deadlines at work, final, the fact I got married this month or str_replace('%my_excuse%', generateRandomExcuse(), 'this email'). any how here is a list of things done. Is is a draft by no means it is meant to be the complete thing !!! changes made to auth include Auth.php *added a Auth::setUseChap(); method, which enable challenge responce (missing is detection of java script capability on the browser, if not this should throw a warning and use the standard auth features) * added an importJS method, this basically includes some java script files it is called by the drawLogin +- changed the drawLogin method, if chap is enabled it uses the java script to change the password to the challenge responce, it allso passes the secret as a hiddent field * added getChallenge method, this return the server to be used currently it just returns the session id but it could be easily changed, everything uses this method to get the challeneg secret Container.php *added a verifyChap method, similar to Container/DB.php *added a fetchChapData, same as fetchLoginData but calls virifyChap instead of verifyPasword, it also passes different parameters to the virifyChap method than verify password ($challenge, $challengeresponce,$entry[$this->options['passwordcol']],$chaptemplate) General structure if chap is enable, some java script files are included oncklick event of the submit button replaces the password with the challenge responce string is chap is enabled and the current container does not have a fetchChap method an die error is thrown else fetchChap is called instead of fetchData fetchChap does the same work as fetchData but it verifies a challenge responce string (using Container::verifyChap method), this is a bit redundant but different data must be passed down the line (fetchData accepts onl username and fetchChapData accepts username, challenge secret, challenge responce) There is something i called a chap template basically it is a template string chich specifies how the chap should be generated is ie '%challenge%%responce%' or '1%responce%-%challenge%', the %fields% would be replaced by the appropriate values. This is merely a consept it has not been implamented see http://mail.itenasolutions.com/~yavo/auth/index.php for a demo and http://mail.itenasolutions.com/~yavo/auth/auth.zip for the code Yavor

« previous php.pear.dev (#16660) next »