Re: About PEAR::Auth() and cookies
| From: | Xavier | Date: | Wed, 21 May 2003 11:10:30 +0000 |
| Subject: | Re: About PEAR::Auth() and cookies | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-5499@lists.php.net to get a copy of this message | ||
Limbourg Arnaud wrote:
Storing a md5 hash in the cookie still forces you to keep the password in clear text on the server to compare with the hash contained in the cookie. Thus it would require a directory with write access on the server. Or there is another way of which i'm not aware (and it's possible ;) Hum, i'm not agree with that, if the password is stored in DB or in the file as a md5 hash , i've just to compare the 2 hashes no ?In DB container there are 3 ways to store password , those are : 'none' equiv plain text , 'md5' and 'crypt'. If Auth is already setted up with the plain text way... Sure that security is really really lacking :) , but if pass are stored as md5, i can compare it with my cookie hash.
To your minds ;), what should be the proper way ? modifying the class itself or creating a new class which extends Auth ?Extend :) Ok :)
regardsI'd like to implement it only for file and DB containers (adding that to other containers definitly doesn't make sense) , in the same way , should i modify or extend them ?Same :) Ok :)