Salt for crypt() in Auth/Container.php
| From: | David Sklar | Date: | Thu, 18 Sep 2003 21:07:04 +0000 |
| Subject: | Salt for crypt() in Auth/Container.php | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-21734@lists.php.net to get a copy of this message | ||
The verifyPassword() method in Auth/Container.php contains the following
code to check a password if the "crypt" cryptType is specified:
return (($password2 == "**" . $password1) ||
(crypt($password1, $password2) == $password2)
);
Why is the check for $password2 == "**".$password1 there? Is there a
backwards compatibility need to allow "encrypted" passwords that consist of
"**" prepended to the cleartext password?
Thanks,
David