Re: Salt for crypt() in Auth/Container.php

From: Date: Fri, 19 Sep 2003 18:29:48 +0000
Subject: Re: Salt for crypt() in Auth/Container.php
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-21799@lists.php.net to get a copy of this message
Am the current maintainer of Auth, but I have no idea what that code does. I also spotted it but following the old paradigm, if is working don't touch (espesially if you don't know what it does :) ) it I did not mess with it. Any of the previous maintainer maybe know, Martin any ideas ??? Yavor David Sklar wrote:
The verifyPassword() method in Auth/Container.php contains the following code to check a password if the "crypt" cryptType is specified: return (($password2 == "**" . $password1) ||
          (crypt($password1, $password2) == $password2)
          );
Why is the check for $password2 == "**".$password1 there? Is there a backwards compatibility need to allow "encrypted" passwords that consist of "**" prepended to the cleartext password? Thanks, David


« previous php.pear.dev (#21799) next »