Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest
| From: | Rui Hirokawa | Date: | Sun, 07 Mar 2004 15:38:30 +0000 |
| Subject: | Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-26174@lists.php.net to get a copy of this message | ||
Hi, Yavor,
Thank you for your suggestion.
I attached a patch to support fetchData($username) for DB container.
If it is accepted, I will change my patch for Auth_HTTP accordingly.
In HTTP Digest Authentication, we can specify 'none' or 'md5' as cryptType.
If cryptType is 'md5', the password assumed to be stored in a1 form
(md5(username:realm:password)).
Rui
On Wed, 03 Mar 2004 18:09:02 +0200
Yavor Shahpasov <yavo@siava.org> wrote:
>
>
> Martin Jansen wrote:
>
> >On Sat Feb 28, 2004 at 11:5821AM +0900, Rui Hirokawa wrote:
> >
> >
> >>And, in the current implementation, password verify process is included
> >>in fetchData method of container class.
> >>
> >>I think container and verification should be clearly divided and
> >>verifyPassword() should be called from Auth class itself, not from
> >>container class.
> >>
> >>I suggest that
> >> fetchData($username, $password) of container class of should be
> >> fetchData($username) to divide verification from container.
> >>
> >>
> >
> >This seems to make sense for me. But you should actually negotiate that
> >with the maintainer of Auth, Yavor Shahpasov, because the containers are
> >all taken from the Auth package.
> >
> >
> >
>
> Since this is basically a BC change, I propose one of the following
> solutions
>
> a) Cheap overload, if only one parameter is passed to fetchData
> ex:
> $authcontainer->fetchData($username) - the user data will be returned in
> an assoc array and false if the user is not found
> $authcontainer->fetchData($username,$password) - wourld work as before
>
> b) Implement a new method fetchUserData which will accept one parameter
> $username and will return the userdata
>
> You should keep in mind that most password are kept in the database in
> an encrypted/hashed form (md5/crypt), am not sure how your
> challenge responce works, but keep in mind that the pass would not be
> the real pass. You mmight need to check the cryptType auth option
> and adjust the verification of the digest.
>
> Let me know which solution you like more.
>
>
> Yavor
>
>
> --
> Yavor Shahpasov
> yavo@siava.org
>
> --
> PEAR Development Mailing List (http://pear.php.net/)
> To unsubscribe, visit: http://www.php.net/unsub.php
--
Rui Hirokawa <rui_hirokawa@ybb.ne.jp>