Re: Auth Challenge Responce

From: Date: Tue, 27 May 2003 18:43:36 +0000
Subject: Re: Auth Challenge Responce
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-16751@lists.php.net to get a copy of this message
Hi, On Sun, 25 May 2003, Yavor Shahpasov wrote: > A while back I asked about this in the list, whether it would be feasible to add such a feature > in Auth. I have implemented a proof of consept modification of it. I know it has taken me a while to > do it you can easily blame my lazines impossible deadlines at work, final, the fact I got married > this month or str_replace('%my_excuse%', generateRandomExcuse(), 'this email'). > any how here is a list of things done. Is is a draft by no means it is meant to be the complete > thing !!! > > changes made to auth include > Auth.php > *added a Auth::setUseChap(); method, which enable challenge responce (missing is detection of > java script capability on the browser, if not this should throw a warning and use the standard auth > features) > * added an importJS method, this basically includes some java script files it is called by the > drawLogin > +- changed the drawLogin method, if chap is enabled it uses the java script to change the > password to the challenge responce, it allso passes the secret as a hiddent field > * added getChallenge method, this return the server to be used currently it just returns the > session id but it could be easily changed, everything uses this method to get the challeneg secret > > Container.php > *added a verifyChap method, similar to > > Container/DB.php > *added a fetchChapData, same as fetchLoginData but calls virifyChap instead of verifyPasword, > it also passes different parameters to the virifyChap method than verify password ($challenge, > $challengeresponce,$entry[$this->options['passwordcol']],$chaptemplate) > > > General structure > if chap is enable, some java script files are included > oncklick event of the submit button replaces the password with the challenge responce string > > is chap is enabled and the current container does not have a fetchChap method an die error is > thrown else fetchChap is called instead of fetchData > after a first look, it looks great (especialy because you implemented most of my suggestions :-D) just two short notes: - you should always inlcude the chapid into the md5-hash, even it's always 1, because otherwise you are breaking the RFC - maybe we can find a way for preparing the auth-class for different chap-methods (ms-chapv1 and v2), this should allow us later easier implement these. bye, -- ------------------------------- ---------------------------------- Michael Bretterklieber - http://www.bretterklieber.com JAWA Management Software GmbH - http://www.jawa.at Tel: ++43-(0)316-403274-12 - GSM: ++43-(0)676-84 03 15 712 ------------------------------- ---------------------------------- "...the number of UNIX installations has grown to 10, with more expected..." - Dennis Ritchie and Ken Thompson, June 1972

« previous php.pear.dev (#16751) next »