Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest

From: Date: Sun, 07 Mar 2004 15:38:30 +0000
Subject: Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-26174@lists.php.net to get a copy of this message
Hi, Yavor, Thank you for your suggestion. I attached a patch to support fetchData($username) for DB container. If it is accepted, I will change my patch for Auth_HTTP accordingly. In HTTP Digest Authentication, we can specify 'none' or 'md5' as cryptType. If cryptType is 'md5', the password assumed to be stored in a1 form (md5(username:realm:password)). Rui On Wed, 03 Mar 2004 18:09:02 +0200 Yavor Shahpasov <yavo@siava.org> wrote: > > > Martin Jansen wrote: > > >On Sat Feb 28, 2004 at 11:5821AM +0900, Rui Hirokawa wrote: > > > > > >>And, in the current implementation, password verify process is included > >>in fetchData method of container class. > >> > >>I think container and verification should be clearly divided and > >>verifyPassword() should be called from Auth class itself, not from > >>container class. > >> > >>I suggest that > >> fetchData($username, $password) of container class of should be > >> fetchData($username) to divide verification from container. > >> > >> > > > >This seems to make sense for me. But you should actually negotiate that > >with the maintainer of Auth, Yavor Shahpasov, because the containers are > >all taken from the Auth package. > > > > > > > > Since this is basically a BC change, I propose one of the following > solutions > > a) Cheap overload, if only one parameter is passed to fetchData > ex: > $authcontainer->fetchData($username) - the user data will be returned in > an assoc array and false if the user is not found > $authcontainer->fetchData($username,$password) - wourld work as before > > b) Implement a new method fetchUserData which will accept one parameter > $username and will return the userdata > > You should keep in mind that most password are kept in the database in > an encrypted/hashed form (md5/crypt), am not sure how your > challenge responce works, but keep in mind that the pass would not be > the real pass. You mmight need to check the cryptType auth option > and adjust the verification of the digest. > > Let me know which solution you like more. > > > Yavor > > > -- > Yavor Shahpasov > yavo@siava.org > > -- > PEAR Development Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php -- Rui Hirokawa <rui_hirokawa@ybb.ne.jp>

« previous php.pear.dev (#26174) next »