Re: Auth - DB_Crypt - any interest?
| From: | Alan Knowles | Date: | Wed, 13 Mar 2002 08:13:23 +0000 |
| Subject: | Re: Auth - DB_Crypt - any interest? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4971@lists.php.net to get a copy of this message | ||
the patch below uses the options["crypttype"], rather than adding a 'set method' - it seemed a little more consistant
I also added this to get the fields back out of the object. - otherwise db_fields seems a little pointless..
if ($this->options["db_fields"])
$this->db_fields = $entry;__I have not tested this YET__ it passed php -l though.. regards alan Index: DB.php =================================================================== RCS file: /repository/pear/Auth/Container/DB.php,v retrieving revision 1.13 diff -u -r1.13 DB.php
--- DB.php 4 Mar 2002 20:44:49 -0000 1.13 +++ DB.php 13 Mar 2002 07:47:33 -0000@@ -195,10 +203,11 @@
$entry = $res->fetchRow(DB_FETCHMODE_ASSOC);
if (is_array($entry)) {
- if ($entry[$this->options['passwordcol']] == md5($password)) {
+ if ($this->validatePasssword($entry[$this->options['passwordcol']],$password)) {
Auth::setAuth($entry[$this->options['usernamecol']]);
$res->free();
-
+ if ($this->options["db_fields"])
+ $this->db_fields = $entry;
return true;
} else {
$this->activeUser = $entry[$this->options['usernamecol']];
@@ -212,6 +221,29 @@
}
// }}}
+ // {{{ validatePassword($password1,$password2)
+
+ /**
+ * Check the entered password against the one in the database
+ *
+ *
+ * @param string Password1 - vistor entered
+ * @param string Password2 from database
+ * @return boolean = TRUE if matched
+ */
+ function validatePassword($password1,$password2)
+ {
+ switch ($this->options['crypttype']) {
+ case "crypt":
+ return
+ (($password2 == "**".$password1) ||
+ ($password2 == crypt($password1,substr($password2,0,2))));
+ case "md5":
+ default:
+ return ($password2 == md5($password1));
+ }
+ }
+ // }}}
// {{{ listUsers()
function listUsers()@@ -260,14 +292,18 @@
$additional_value .= ", '" . $value . "'";
}
}
-
+ + $function = "md5";
+ if ($this->options['crypttype'])
+ $function = $this->options['crypttype'];
+ $query = sprintf("INSERT INTO %s (%s, %s%s) VALUES ('%s', '%s'%s)",
$this->options['table'],
$this->options['usernamecol'],
$this->options['passwordcol'],
$additional_key,
$username,
- md5($password),
+ $function($password),
$additional_value
);
@@ -310,4 +346,4 @@
// }}}} -?> +?> \ No newline at end of file Martin Jansen wrote:
On Mon, 11 Mar 2002 11:57:56 +0100 (CET), Hans Westerbeek wrote:Anyway I need support for several cryptotypes as well. How about using DES as default and adding a setCryptoType() method? I'd be happy to implement it, but let's agree on the interface first.I've also thought about having something like that. I think we could do it like that: Container/DB.php: ====================================================================== var $cryptType = "md5"; function setCryptType($type = "md5") { $this->cryptType = $type; } function validatePassword($password1, $password2) { switch ($this->cryptType) {case "crypt" :/** do crypt encryption here */case "md5" : default : $password1 = md5($password1)} if ($password1 == $password2) {return true;} else {return false;} } ====================================================================== If you want to implement this, you can send me the diffs. - Martin