Re: Auth - DB_Crypt - any interest?

From: Date: Wed, 13 Mar 2002 08:13:23 +0000
Subject: Re: Auth - DB_Crypt - any interest?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4971@lists.php.net to get a copy of this message
the patch below uses the options["crypttype"], rather than adding a 'set method' - it seemed a little more consistant I also added this to get the fields back out of the object. - otherwise db_fields seems a little pointless.. if ($this->options["db_fields"])
                       $this->db_fields = $entry;
__I have not tested this YET__ it passed php -l though.. regards alan Index: DB.php =================================================================== RCS file: /repository/pear/Auth/Container/DB.php,v retrieving revision 1.13 diff -u -r1.13 DB.php
--- DB.php    4 Mar 2002 20:44:49 -0000    1.13
+++ DB.php    13 Mar 2002 07:47:33 -0000
@@ -195,10 +203,11 @@
            $entry = $res->fetchRow(DB_FETCHMODE_ASSOC);
            if (is_array($entry)) {
-                if ($entry[$this->options['passwordcol']] == md5($password)) {
+                if ($this->validatePasssword($entry[$this->options['passwordcol']],$password)) {
                    Auth::setAuth($entry[$this->options['usernamecol']]);
                    $res->free();
-
+                    if ($this->options["db_fields"])
+                        $this->db_fields = $entry;
                    return true;
                } else {
                    $this->activeUser = $entry[$this->options['usernamecol']];
@@ -212,6 +221,29 @@
    }
    // }}}
+    // {{{ validatePassword($password1,$password2)
+
+    /**
+     * Check the entered password against the one in the database
+     *
+     *
+     * @param   string Password1 - vistor entered
+     * @param   string Password2 from database
+     * @return  boolean = TRUE if matched
+     */
+    function validatePassword($password1,$password2)
+    {
+        switch ($this->options['crypttype']) {
+            case "crypt":
+                return
+                    (($password2 == "**".$password1) ||
+                    ($password2 == crypt($password1,substr($password2,0,2))));
+            case "md5":
+            default:
+                return ($password2 == md5($password1));
+        }
+    }
+    // }}}
    // {{{ listUsers()
    function listUsers()
@@ -260,14 +292,18 @@
                $additional_value .= ", '" . $value . "'";
            }
        }
-
+       +        $function = "md5";
+        if ($this->options['crypttype'])
+            $function = $this->options['crypttype'];
+                   $query = sprintf("INSERT INTO %s (%s, %s%s) VALUES ('%s', '%s'%s)",
                         $this->options['table'],
                         $this->options['usernamecol'],
                         $this->options['passwordcol'],
                         $additional_key,
                         $username,
-                         md5($password),
+                         $function($password),
                         $additional_value
                         );
@@ -310,4 +346,4 @@
    // }}}
} -?> +?> \ No newline at end of file Martin Jansen wrote:
On Mon, 11 Mar 2002 11:57:56 +0100 (CET), Hans Westerbeek wrote:
Anyway I need support for several cryptotypes as well. How about using DES as default and adding a setCryptoType() method? I'd be happy to implement it, but let's agree on the interface first.
I've also thought about having something like that. I think we could do it like that: Container/DB.php: ====================================================================== var $cryptType = "md5"; function setCryptType($type = "md5") { $this->cryptType = $type; } function validatePassword($password1, $password2) { switch ($this->cryptType) {
         case "crypt" :
      /** do crypt encryption here */
    case "md5" :
    default :
              $password1 = md5($password1)
} if ($password1 == $password2) {
      return true;
} else {
      return false;
} } ====================================================================== If you want to implement this, you can send me the diffs. - Martin


« previous php.pear.dev (#4971) next »