Re: Auth Challenge Responce
| From: | Michael Bretterklieber | Date: | Tue, 27 May 2003 18:43:36 +0000 |
| Subject: | Re: Auth Challenge Responce | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-16751@lists.php.net to get a copy of this message | ||
Hi,
On Sun, 25 May 2003, Yavor Shahpasov wrote:
> A while back I asked about this in the list, whether it would be feasible to add such a feature
> in Auth. I have implemented a proof of consept modification of it. I know it has taken me a while to
> do it you can easily blame my lazines impossible deadlines at work, final, the fact I got married
> this month or str_replace('%my_excuse%', generateRandomExcuse(), 'this email').
> any how here is a list of things done. Is is a draft by no means it is meant to be the complete
> thing !!!
>
> changes made to auth include
> Auth.php
> *added a Auth::setUseChap(); method, which enable challenge responce (missing is detection of
> java script capability on the browser, if not this should throw a warning and use the standard auth
> features)
> * added an importJS method, this basically includes some java script files it is called by the
> drawLogin
> +- changed the drawLogin method, if chap is enabled it uses the java script to change the
> password to the challenge responce, it allso passes the secret as a hiddent field
> * added getChallenge method, this return the server to be used currently it just returns the
> session id but it could be easily changed, everything uses this method to get the challeneg secret
>
> Container.php
> *added a verifyChap method, similar to
>
> Container/DB.php
> *added a fetchChapData, same as fetchLoginData but calls virifyChap instead of verifyPasword,
> it also passes different parameters to the virifyChap method than verify password ($challenge,
> $challengeresponce,$entry[$this->options['passwordcol']],$chaptemplate)
>
>
> General structure
> if chap is enable, some java script files are included
> oncklick event of the submit button replaces the password with the challenge responce string
>
> is chap is enabled and the current container does not have a fetchChap method an die error is
> thrown else fetchChap is called instead of fetchData
>
after a first look, it looks great (especialy because you implemented most
of my suggestions :-D)
just two short notes:
- you should always inlcude the chapid into the md5-hash, even it's always
1, because otherwise you are breaking the RFC
- maybe we can find a way for preparing the auth-class for different
chap-methods (ms-chapv1 and v2), this should allow us later easier
implement these.
bye,
--
------------------------------- ----------------------------------
Michael Bretterklieber - http://www.bretterklieber.com
JAWA Management Software GmbH - http://www.jawa.at
Tel: ++43-(0)316-403274-12 - GSM: ++43-(0)676-84 03 15 712
------------------------------- ----------------------------------
"...the number of UNIX installations has grown to 10, with more
expected..." - Dennis Ritchie and Ken Thompson, June 1972