Re: LiveUser::decryptPW
| From: | Matthias Nothhaft | Date: | Tue, 30 May 2006 11:27:09 +0000 |
| Subject: | Re: LiveUser::decryptPW | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-42689@lists.php.net to get a copy of this message | ||
Lukas Smith wrote:
> Matthias Nothhaft wrote:
>> Lukas Smith wrote:
>>> Matthias Nothhaft wrote:
>>>> Hi,
>>>>
>>>> in CVS I believe decryptPW should "return $encryptedPW;" at the end of
>>>> the function instead of $decryptedPW
>>>>
>>>> Furthermore $plainPW is not set but returned.. So someone should
>>>> probably check this again?
>>> thxy for the heads up!
>>>
>>> please check CVS .. i just commited some improvements ..
>> hm.. in my good old LU version md5 is returned as it is, so why do you
>> push an error in this case?
>>
>>
>> It it a new concept to not use decryption if not possible?
>
> Not really a "concept" ..
> But I think its cleaner and you can easily handle the error in userland,
> where as it was previously not possible to determine if the password was
> actually decrypted or not.
maybe a isDecryptable($pw, $mode) or similar function would be a better
approach but pushing an error!?
or maybe something like encryptionModeSupports('decrypt') ?
Regards,
Matthias