Re: [patch] Auth to have case sensitive username matching in DB container
| From: | Alan Knowles | Date: | Thu, 13 May 2004 02:46:26 +0000 |
| Subject: | Re: [patch] Auth to have case sensitive username matching in DB container | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-29168@lists.php.net to get a copy of this message | ||
It should go in the bug system - theoretically it wont get forgotton there (/me wonders what's happened to the bug summary emails...)
Regards
alan
[php]Walter wrote:
I just "discovered" that the DB container within Auth does not do case sensitive username validation. I can only image that it leaves this bit of "security" to the DB being used. This is an issue with us. It may, or may not, be for others. So with this in mind, I've created a "patch" to correct this. NOTE: I've not touched the other containers with this. I would like to submit it to the Auth folks for consideration. There are 2 options given here. 1) =============================== - Auth.php Add this anywhere in the properies area of the class definition (toward top). I put it after "$_postPassword". /*** A boolean to have case sensitive validation on USERNAME* Defaults to FALSE for BC* @var boolean */var $_ckCase = false; I also added this after "getStatus()" // {{{ setCaseCheck() /*** Set boolean to have Auth do a case sensitive check on username* against returned container value* * @access public * @param boolean ckCase * @return void */function setCaseCheck( $ckCase = false ) {$this->_ckCase = $ckCase;} // }}} // {{{ getCaseCheck() /*** Get boolean to have Auth do a case sensitive check on username* against container value* * @access public * @return boolean ckCase */function getCaseCheck() {return $this->_ckCase;} // }}} - Auth/container/DB.php Insert this block at line 268. After "if (!is_array($res)) { ... }" // Some databases perform case-insensitive SELECTs. // This works around that // See if username is a case-sensitive match to what came back from DB if ( ( $this->_auth_obj->getCaseCheck() ) && ( $res[$this->options['usernamecol']] != $username ) ) {$this->activeUser = ''; return false; }And you can turn this "feature" on with... // Set case sensitivity $objAuth->setCaseCheck( true ); 2) =============================== Or, to make it real simple to "fix", simply hang it off the new "advancedsecurity" flag... // Some databases perform case-insensitive SELECTs. // This works around that // See if username is a case-sensitive match to what came back from DB if ( ( $this->_auth_obj->advancedSecurity ) && ( $res[$this->options['usernamecol']] != $username ) ) {$this->activeUser = ''; return false; }=============================== I hope this is the right place for this. Walter