Pear Auth problems

From: Date: Fri, 05 Dec 2003 00:04:53 +0000
Subject: Pear Auth problems
Groups: php.pear.general 
Request: Send a blank email to pear-general+get-9306@lists.php.net to get a copy of this message
If this is not the forum for this topic I apologize and would appreciate tips on where to find info. I am experimenting with the Auth module using a local file as the db. I have struggled to figure out what to put in the passwd file as the password. Here is what I have for the environment: on a redhat 7.3 test box : [root@bretsony Container]# rpm -qa|grep php php-4.1.2-7.3.6 php-pgsql-4.1.2-7.3.6 php-manual-4.1.2-7.3.6 [root@bretsony Container]# pear list Installed packages: =================== Package Version State Archive_Tar 1.1 stable Auth 1.2.2 stable Auth_HTTP 2.0 stable Console_Getopt 1.0 stable DB 1.5.0RC2 stable Mail 1.1.2 stable Net_SMTP 1.2.3 stable Net_Socket 1.0.1 stable PEAR 1.3b3 beta XML_Parser 1.0.1 stable XML_RPC 1.0.4 stable [root@bretsony Container]# rpm -q apache apache-1.3.27-3 I instantiate the Auth object with the following code: require_once "Auth/Auth.php"; function loginFunction() { /** * Change the HTML output so that it fits to your * application. */ echo "<form method=\"post\" action=\"" . $_SERVER['PHP_SELF'] . "\">"; echo "<input type=\"text\" name=\"username\">"; echo "<input type=\"password\" name=\"password\">"; echo "<input type=\"submit\">"; echo "</form>"; } $a = new Auth("File", "/$env/elegroups/.auth"); $a->start(); if ($a->getAuth()) { print "this is authenticated text"; /** * The output of your site goes here. */ } what I have finally found is the following: The verifyPassword function that gets called is the one in pear/File/Passwd.php as part of the File_Passwd object and it does not understand md5 The default function used by crypt on this platform is m5d and uses a 12 character salt. This can be tested by examining the constant CRYPT_SALT_LENGTH I can't see how that verifyPassword in pear/Auth/Container.php can get called since the call to verifyPassword is in pear/Auth/Container/File.php fetchData() and looks like this: $result = $this->pwfile->verifyPassword($username, $password); and pwfile is a File_Passwd object instantiated in the constructor. and is defined in pear/File/Passwd.php What Am I doing wrong? I finally got it to authenticate by modifying File_Password->verifyPassword and trimming the stored value of the hash and using CRYPT_SALT_LENGTH but I think I am still doing something wrong to have to do this. Here is the modification. verifyPassword($user,$pass) { if(isset($this->users[$user])) { if(trim($this->users[$user]) == crypt($pass,substr($this->users[$user],0,CRYPT_SALT_LENGTH))) { return true; } } return false; } // end func verifyPassword() Tips appreciated Bret

« previous php.pear.general (#9306) next »