RE: [PEAR] About PEAR::Auth() and cookies
| From: | LIMBOURG Arnaud | Date: | Wed, 21 May 2003 10:56:27 +0000 |
| Subject: | RE: [PEAR] About PEAR::Auth() and cookies | ||
| Groups: | php.pear.general | ||
| Request: | Send a blank email to pear-general+get-5498@lists.php.net to get a copy of this message | ||
> Hi all,
> As an OOP exercise, i'd like to work on PEAR::Auth() and
> implementing a
> Cookie based auth support.
>
> I know that cookie based Auth is not recommended for evident security
> issues, but i think it can be a really cool feature for
> websites where
> security is no big deal.
> for thoses sites, i plan to store plain login and pass datas as md5
> hashe. I've seen that in LiveUser, the cookie based auth use only the
> loginname. But i'd prefer add the password hash.
Yes, and it breaks because it does that :)
Storing a md5 hash in the cookie still forces you to keep the password in
clear text on the server to compare with the hash contained in the cookie.
Thus it would require a directory with write access on the server. Or there
is another way of which i'm not aware (and it's possible ;)
> To your minds ;), what should be the proper way ? modifying the class
> itself or creating a new class which extends Auth ?
Extend :)
> I'd like to implement it only for file and DB containers
> (adding that to
> other containers definitly doesn't make sense) , in the same way ,
> should i modify or extend them ?
Same :)