[PEPr] Comment on Authentication::Auth_HTTP_Digest

From: Date: Fri, 20 Feb 2004 05:06:27 +0000
Subject: [PEPr] Comment on Authentication::Auth_HTTP_Digest
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-25735@lists.php.net to get a copy of this message
Paul Querna (http://pear.php.net/user/chip) has commented on the proposal for Authentication::Auth_HTTP_Digest. Comment: In the $algorithm doc you say: * hash algorithm (MD5|MD5-sess) However MD5-sess does not seem to be properly supported. Therefore it should not be a valid argument for the algorithum. apache_request_headers - It would be nice to allow this code to work from CGI based PHP. Im not sure it is completely possible, but alternatives should be investigated. On line 210: if ($_SERVER['REQUEST_URI'] == $auth['uri']) { If you look in the Apache implementation[1] in mod_auth_digest.c: if (strcmp(resp->uri, resp->raw_request_uri)) { /* Hmm, the simple match didn't work (probably a proxy modified the * request-uri), so lets do a more sophisticated match */ It then goes on todo a detailed comparison of the URLs. It seems that Apache's implementation should be followed. Why does this module support both Basic and Digest, when it is named 'Auth_HTTP_Digest'. This doesn't make any sense. Also, you should error out if a client is sending Basic Auth to a digest protected area. This is how Apache behaves. If you want the Package to support both Digest and Basic, I would suggest first renaming the Package, and 2nd allowing the user to set a flag 'force digest only'. $this->username is passed into an sql query on line 274 without any escaping. $this->username is taken directly from the HTTP Headers. SQL Injection Attack is just waiting to happen. [1] - http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/aaa/mod_auth_digest.c?rev=1.85&view=auto Proposal information: http://pear.php.net/pepr/pepr-proposal-show.php?id=25 -- Sent by PEPr, the automatic proposal system at http://pear.php.net

« previous php.pear.dev (#25735) next »