Auth - input of username and password, verifyPassword extension
| From: | Christian Weiske | Date: | Mon, 22 Nov 2004 10:10:24 +0000 |
| Subject: | Auth - input of username and password, verifyPassword extension | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-34485@lists.php.net to get a copy of this message | ||
Hi
[reading the following paragraph is not necessary to understand my suggestions]
--------------------------
This night I had an idea how to automatically log in into web pages without inserting usernames and passwords:
The target login page provides a "autologin" link which, when called, tries to send an XML-RPC Request to the calling IP (user's machine), requesting the username and the password. If the user has installed such an XML-RPC server, it responds with the username and a crypted password. This password is a crypt/md5 of "<timestamp><password>"; the timestamp has been sent with the request. Encryption of the timestamp is required as anybody can act as a server and, if sniffed such a request, log on with the user's data.
Now the web page takes the username, fetches the password from whatever source and applies the same crypt/md5 with the timestamp. If the passwords match, the user gets logged in without having typed a thing.
----------------------
Now using Auth for logging into web pages with input username and password coming from a different source than a web form (POST request) is not possible, except you set the $_POST data before authenticating.
As this no good programming practise, I propose that suggest that the Auth class should be extendet to support any function (as callback) to get an array of username/password combination. By default, this should be the in-built POST function to ensure BC and to keep use of Auth as easy as it is now. The user can now register a function to be called when username/password is needed, and this one could do such a thing like described in the first paragraph.
Second:
The verifyPassword function of the Auth_Container class doesn't support authentication in which the original password is hashed with a variable string:
One can have a md5'ed pw in the DB or somewhere and check if the md5 of the input password matches the password stored in the db.
It is not possible, to apply a md5/somewhat function the password stored in the DB/somewhere and check if it matches the input password. This functionality is needed when the input password comes through an unsecure channel and needs to be crypted with a salt or timestamp to prevent using sniffed passwords to re-authenticate.
Writing my own container is not an option, as this would stop the use of other containers for authentication.
Do you see the need of support for such things? If yes, do you think that Auth is the right place for it?
Regards/MfG,
Christian Weiske
--
XMMS is playing now:
Dido - Dont Leave Home
Attachment: [application/pgp-signature] OpenPGP digital signature signature.asc
Attachment: [application/pgp-signature] OpenPGP digital signature signature.asc