[PEPr] Comment on Authentication::Auth_HTTP_Digest
| From: | PEPr | Date: | Fri, 20 Feb 2004 05:06:27 +0000 |
| Subject: | [PEPr] Comment on Authentication::Auth_HTTP_Digest | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-25735@lists.php.net to get a copy of this message | ||
Paul Querna (http://pear.php.net/user/chip) has commented on the proposal for
Authentication::Auth_HTTP_Digest.
Comment:
In the $algorithm doc you say:
* hash algorithm (MD5|MD5-sess)
However MD5-sess does not seem to be properly supported. Therefore it should not be a valid
argument for the algorithum.
apache_request_headers - It would be nice to allow this code to work from CGI based PHP. Im not
sure it is completely possible, but alternatives should be investigated.
On line 210:
if ($_SERVER['REQUEST_URI'] == $auth['uri']) {
If you look in the Apache implementation[1] in mod_auth_digest.c:
if (strcmp(resp->uri, resp->raw_request_uri)) {
/* Hmm, the simple match didn't work (probably a proxy modified the
* request-uri), so lets do a more sophisticated match
*/
It then goes on todo a detailed comparison of the URLs. It seems that Apache's implementation
should be followed.
Why does this module support both Basic and Digest, when it is named 'Auth_HTTP_Digest'.
This doesn't make any sense.
Also, you should error out if a client is sending Basic Auth to a digest protected area. This is how
Apache behaves. If you want the Package to support both Digest and Basic, I would suggest first
renaming the Package, and 2nd allowing the user to set a flag 'force digest only'.
$this->username is passed into an sql query on line 274 without any escaping. $this->username
is taken directly from the HTTP Headers. SQL Injection Attack is just waiting to happen.
[1] - http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/aaa/mod_auth_digest.c?rev=1.85&view=auto
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=25
--
Sent by PEPr, the automatic proposal system at http://pear.php.net