Re: Salt for crypt() in Auth/Container.php
| From: | Yavor Shahpasov | Date: | Fri, 19 Sep 2003 18:29:48 +0000 |
| Subject: | Re: Salt for crypt() in Auth/Container.php | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-21799@lists.php.net to get a copy of this message | ||
Am the current maintainer of Auth, but I have no idea what that code does. I also spotted it but following the old paradigm, if is working don't touch (espesially if you don't know what it does :) ) it I did not mess with it.
Any of the previous maintainer maybe know, Martin any ideas ???
Yavor
David Sklar wrote:
The verifyPassword() method in Auth/Container.php contains the following
code to check a password if the "crypt" cryptType is specified:
return (($password2 == "**" . $password1) ||
(crypt($password1, $password2) == $password2)
);
Why is the check for $password2 == "**".$password1 there? Is there a
backwards compatibility need to allow "encrypted" passwords that consist of
"**" prepended to the cleartext password?
Thanks,
David