Pear Auth problems
| From: | Bret Hughes | Date: | Fri, 05 Dec 2003 00:04:53 +0000 |
| Subject: | Pear Auth problems | ||
| Groups: | php.pear.general | ||
| Request: | Send a blank email to pear-general+get-9306@lists.php.net to get a copy of this message | ||
If this is not the forum for this topic I apologize and would appreciate
tips on where to find info.
I am experimenting with the Auth module using a local file as the db.
I have struggled to figure out what to put in the passwd file as the
password.
Here is what I have for the environment:
on a redhat 7.3 test box :
[root@bretsony Container]# rpm -qa|grep php
php-4.1.2-7.3.6
php-pgsql-4.1.2-7.3.6
php-manual-4.1.2-7.3.6
[root@bretsony Container]# pear list
Installed packages:
===================
Package Version State
Archive_Tar 1.1 stable
Auth 1.2.2 stable
Auth_HTTP 2.0 stable
Console_Getopt 1.0 stable
DB 1.5.0RC2 stable
Mail 1.1.2 stable
Net_SMTP 1.2.3 stable
Net_Socket 1.0.1 stable
PEAR 1.3b3 beta
XML_Parser 1.0.1 stable
XML_RPC 1.0.4 stable
[root@bretsony Container]# rpm -q apache
apache-1.3.27-3
I instantiate the Auth object with the following code:
require_once "Auth/Auth.php";
function loginFunction()
{
/**
* Change the HTML output so that it fits to your
* application.
*/
echo "<form method=\"post\" action=\"" .
$_SERVER['PHP_SELF'] .
"\">";
echo "<input type=\"text\" name=\"username\">";
echo "<input type=\"password\" name=\"password\">";
echo "<input type=\"submit\">";
echo "</form>";
}
$a = new Auth("File", "/$env/elegroups/.auth");
$a->start();
if ($a->getAuth()) {
print "this is authenticated text";
/**
* The output of your site goes here.
*/
}
what I have finally found is the following:
The verifyPassword function that gets called is the one in
pear/File/Passwd.php as part of the File_Passwd object and it does not
understand md5
The default function used by crypt on this platform is m5d and uses a 12
character salt. This can be tested by examining the constant
CRYPT_SALT_LENGTH
I can't see how that verifyPassword in pear/Auth/Container.php can get
called since the call to verifyPassword is in
pear/Auth/Container/File.php fetchData() and looks like this:
$result = $this->pwfile->verifyPassword($username, $password);
and pwfile is a File_Passwd object instantiated in the constructor. and
is defined in pear/File/Passwd.php
What Am I doing wrong?
I finally got it to authenticate by modifying
File_Password->verifyPassword and trimming the stored value of the hash
and using CRYPT_SALT_LENGTH but I think I am still doing something wrong
to have to do this.
Here is the modification.
verifyPassword($user,$pass) {
if(isset($this->users[$user])) {
if(trim($this->users[$user]) ==
crypt($pass,substr($this->users[$user],0,CRYPT_SALT_LENGTH)))
{
return true;
}
}
return false;
} // end func verifyPassword()
Tips appreciated
Bret