Re: bug in Auth 1.2.3 ?

From: Date: Fri, 16 Jan 2004 17:37:23 +0000
Subject: Re: bug in Auth 1.2.3 ?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-25102@lists.php.net to get a copy of this message
Fixed in CVS, thanks for spotting that Yavor Jeroen Houben wrote:
Hi, I spotted some code in the latest Auth.php that I think contains a bug. The FailedLoginCallback function is called *before* this bit of code:
               if (!empty($this->username) && !$login_ok) {
                   $this->status = AUTH_WRONG_LOGIN;
               }
So on a wrong login, the status is never changed because a reference to the Auth object is passed to the function before the status is changed. I've attached a diff from the latest CVS version (i've followed the instructions on how to do this from the PEAR webpages). Cheers Jeroen ------------------------------------------------------------------------ ? Auth.diff Index: Auth.php =================================================================== RCS file: /repository/pear/Auth/Auth.php,v retrieving revision 1.69 diff -u -r1.69 Auth.php --- Auth.php 18 Dec 2003 10:36:03 -0000 1.69 +++ Auth.php 16 Jan 2004 11:07:28 -0000 @@ -292,6 +292,9 @@
            if (true === $this->storage->fetchData($this->username, $this->password)) {
                $login_ok = true;
            } else {
+                if (!empty($this->username) && !$login_ok) {
+                    $this->status = AUTH_WRONG_LOGIN;
+                }
                if (is_callable($this->loginFailedCallback)) {
                    call_user_func($this->loginFailedCallback,$this->username, $this);
                }
@@ -309,10 +312,6 @@
         * If the login failed or the user entered no username,
         * output the login screen again.
         */
-        if (!empty($this->username) && !$login_ok) {
-            $this->status = AUTH_WRONG_LOGIN;
-        }
-
        if ((empty($this->username) || !$login_ok) && $this->showLogin) {
            $this->drawLogin($this->storage->activeUser);
            return;
@@ -878,4 +877,4 @@
    // }}}
} -?> \ No newline at end of file +?>


« previous php.pear.dev (#25102) next »