Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest

From: Date: Wed, 10 Mar 2004 22:15:46 +0000
Subject: Re: [PEPr] Call for votes on Authentication::Auth_HTTP_Digest
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-26269@lists.php.net to get a copy of this message
Hi, Yavor, I send my previous mail again because attached file was removed on pear-dev. Thank you for your suggestion. I attached a patch to support fetchData($username) for DB container. If it is accepted, I will change my patch for Auth_HTTP accordingly. In HTTP Digest Authentication, we can specify 'none' or 'md5' as cryptType. If cryptType is 'md5', the password assumed to be stored in a1 form (md5(username:realm:password)). Rui Index: Container.php =================================================================== RCS file: /repository/pear/Auth/Container.php,v retrieving revision 1.16 diff -c -r1.16 Container.php *** Container.php 9 Feb 2004 20:24:32 -0000 1.16 --- Container.php 7 Mar 2004 14:16:19 -0000 *************** *** 58,66 **** * * Has to be overwritten by each storage class * * @access public */ ! function fetchData() { } --- 58,68 ---- * * Has to be overwritten by each storage class * + * @param string Entered username + * @param string Entered password * @access public */ ! function fetchData($username, $password == '') { } Index: Container/DB.php =================================================================== RCS file: /repository/pear/Auth/Container/DB.php,v retrieving revision 1.43 diff -c -r1.43 DB.php *** Container/DB.php 21 Feb 2004 21:22:47 -0000 1.43 --- Container/DB.php 7 Mar 2004 14:16:19 -0000 *************** *** 219,227 **** * * @param string Username * @param string Password ! * @return mixed Error object or boolean */ ! function fetchData($username, $password) { // Prepare for a database query $err = $this->_prepare(); --- 219,227 ---- * * @param string Username * @param string Password ! * @return mixed Error object or boolean, passoword if $password is empty */ ! function fetchData($username, $password = '') { // Prepare for a database query $err = $this->_prepare(); *************** *** 264,269 **** --- 264,274 ---- $this->activeUser = ''; return false; } + + if (empty($password)) { + return trim($res[$this->options['passwordcol']], "\r\n"); + } + if ($this->verifyPassword(trim($password, "\r\n"), trim($res[$this->options['passwordcol']], "\r\n"), $this->options['cryptType'])) { On Wed, 03 Mar 2004 18:09:02 +0200 Yavor Shahpasov <yavo@siava.org> wrote: > > > Martin Jansen wrote: > > >On Sat Feb 28, 2004 at 11:5821AM +0900, Rui Hirokawa wrote: > > > > > >>And, in the current implementation, password verify process is included > >>in fetchData method of container class. > >> > >>I think container and verification should be clearly divided and > >>verifyPassword() should be called from Auth class itself, not from > >>container class. > >> > >>I suggest that > >> fetchData($username, $password) of container class of should be > >> fetchData($username) to divide verification from container. > >> > >> > > > >This seems to make sense for me. But you should actually negotiate that > >with the maintainer of Auth, Yavor Shahpasov, because the containers are > >all taken from the Auth package. > > > > > > > > Since this is basically a BC change, I propose one of the following > solutions > > a) Cheap overload, if only one parameter is passed to fetchData > ex: > $authcontainer->fetchData($username) - the user data will be returned in > an assoc array and false if the user is not found > $authcontainer->fetchData($username,$password) - wourld work as before > > b) Implement a new method fetchUserData which will accept one parameter > $username and will return the userdata > > You should keep in mind that most password are kept in the database in > an encrypted/hashed form (md5/crypt), am not sure how your > challenge responce works, but keep in mind that the pass would not be > the real pass. You mmight need to check the cryptType auth option > and adjust the verification of the digest. > > Let me know which solution you like more. > > > Yavor > > > -- > Yavor Shahpasov > yavo@siava.org > > -- > PEAR Development Mailing List (http://pear.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php -- Rui Hirokawa <rui_hirokawa@ybb.ne.jp>

« previous php.pear.dev (#26269) next »