Re: Unofficial PEAR meeting summary
| From: | Paul M Jones | Date: | Fri, 07 May 2004 11:29:52 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28950@lists.php.net to get a copy of this message | ||
On May 7, 2004, at 1:59 AM, Cipriano Groenendal wrote:
OK, we're back to open editing now, no need to sign in. It was fun while it lasted.On Thu May 06, 2004 at 10:3433PM +0200, Cipriano Groenendal wrote:If you look at Auth/Container/PEAR.php, you'll see that the Auth package uses an RPC call to get userinfo. Within taht is the md5sum of the pass, which is compared to a locally md5'd password string. Wether this is by design, or a bug, in cases like this it's quite cool :)That's definitively a bug! If I don't hear any *good* objections, I'll remove the password from the return value of user.info at the weekend.
Well, the only objection against that that I can think off, would be that it breaks anything using Auth_PEAR, such as Paul's Yawiki for pear-dev only...Which is no big deal in the short term, but in the long term it would be nice to be able to use the PEAR credentials. -- Paul M. Jones Savant: the simple alternative to Smarty for PHP. http://phpsavant.com/ DB_Table: build RDBMS tables and XHTML forms in one PHP class. http://wiki.ciaweb.net/yawiki/index.php?area=DB_Table Yawiki: your collaborative online documentation system. http://wiki.ciaweb.net/yawiki/index.php?area=Yawiki