Re: pecl.php.net auth from master.php.net

From: Date: Sun, 26 Jun 2011 18:00:06 +0000
Subject: Re: pecl.php.net auth from master.php.net
References: 1 2 3 4  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-11294@lists.php.net to get a copy of this message
On Sun, Jun 26, 2011 at 7:16 PM, Hannes Magnusson <hannes.magnusson@gmail.com> wrote: > On Sun, Jun 26, 2011 at 19:09, Ferenc Kovacs <tyra3l@gmail.com> wrote: >> On Sun, Jun 26, 2011 at 5:44 PM, Hannes Magnusson >> <hannes.magnusson@gmail.com> wrote: >>> On Sun, Jun 26, 2011 at 03:00, Ferenc Kovacs <tyra3l@gmail.com> wrote: >>>> Hi. >>>> >>>> I've started implementing the master authentication into the peclweb >>>> codebase, this was we wouldn't have to store passwords there. >>>> I've successively implemented the login/logout stuff, and it is >>>> working (you need the AUTH_TOKEN environment variable to be set to be >>>> able to test this). >>>> I wanted to ask your opinion about the diff, before proceeding. >>>> more info about this change can be found on >>>> https://wiki.php.net/pecl/web/todo >>> >>> I don't think you can drop users without svn account as there are a >>> good number of exts that do not use our svn, so not all authors do >>> have svn accounts. >>> >>> Also, there is no guarantee that pecl usernames map correctly to the >>> svn usernames... >>> >>> If you have however taken this into account and checked if there >>> aren't that many 'edge cases', then I don't have any objections :) >>> >>> -Hannes >>> >> >> Hi. >> >> Pierre said that it could/should be done this way. >> I will look into this, but Pierre suggested that we should fix the >> problematic users on case-by-case basis. >> btw: what do you think about the patch? > > > If you sent one, it didn't come through. The list stripsout pretty > much everything except for text/plain > > -Hannes > I was afraid of this. :/ attaching again with .txt extension. Tyrael

Index: pear-auth.php =================================================================== --- pear-auth.php (revision 312202) +++ pear-auth.php (working copy) @@ -89,47 +89,26 @@ { global $dbh, $auth_user; + $error = ''; + $ok = false; + if (empty($auth_user)) { $auth_user = new PEAR_User($dbh, $user); } - $error = ''; - $ok = false; - switch (strlen(@$auth_user->password)) { - // handle old-style DES-encrypted passwords - case 13: { - $seed = substr($auth_user->password, 0, 2); - $crypted = crypt($passwd, $seed); - if ($crypted == @$auth_user->password) { - $ok = true; - } else { - $error = "pear-auth: user `$user': invalid password (des)"; - } - break; - } - // handle new-style MD5-encrypted passwords - case 32: { - // Check if the passwd is already md5()ed - if (preg_match('/^[a-z0-9]{32}$/', $passwd)) { - $crypted = $passwd; - } else { - $crypted = md5($passwd); - } - - if ($crypted == @$auth_user->password) { - $ok = true; - } else { - $error = "pear-auth: user `$user': invalid password (md5)"; - } - break; - } - } + if (empty($auth_user->registered)) { if ($user) { $error = "pear-auth: user `$user' not registered"; } $ok = false; } + + if(auth_verify_master($user, $passwd)) { + $ok = true; + } + if ($ok) { + $_SESSION["credentials"] = array('user' => $user, 'password' => $passwd); $auth_user->_readonly = true; return auth_check("pear.user"); } @@ -140,6 +119,41 @@ return false; } +function auth_verify_master($user, $pass) +{ + $post = http_build_query( + array( + 'token' => getenv('AUTH_TOKEN'), + 'username' => $user, + 'password' => $pass, + ) + ); + + $opts = array( + 'method' => 'POST', + 'header' => 'Content-type: application/x-www-form-urlencoded', + 'content' => $post, + ); + + $ctx = stream_context_create(array('http' => $opts)); + + $s = file_get_contents('https://master.php.net/fetch/cvsauth.php', false, $ctx); + + $a = @unserialize($s); + if (!is_array($a)) { + $error = "Failed to get authentication information.Maybe master is down?"; + error_log("$error\n", 3, PEAR_TMPDIR . DIRECTORY_SEPARATOR . 'pear-errors.log'); + return false; + } + if (isset($a['errno'])) { + $error = "Authentication failed: {$a['errstr']}"; + error_log("$error\n", 3, PEAR_TMPDIR . DIRECTORY_SEPARATOR . 'pear-errors.log'); + return false; + } + + return true; +} + function auth_check($atom) { global $dbh; @@ -229,6 +243,8 @@ preg_replace('/logout=1/', '', $_SERVER['QUERY_STRING'])); } + unset($_SESSION); + session_destroy(); } $cvspasswd_file = "/repository/CVSROOT/passwd"; @@ -273,22 +289,8 @@ return true; } $auth_user = new PEAR_User($dbh, $_COOKIE['PEAR_USER']); - switch (strlen(@$auth_user->password)) { - // handle old-style DES-encrypted passwords - case 13: { - $seed = substr($auth_user->password, 0, 2); - if (crypt($_COOKIE['PEAR_PW'], $seed) == @$auth_user->password) { - return true; - } - break; - } - // handle new-style MD5-encrypted passwords - case 32: { - if (md5($_COOKIE['PEAR_PW']) == @$auth_user->password) { - return true; - } - break; - } + if(auth_verify_master($_COOKIE['PEAR_USER'], $_SESSION['credentials']['password'])) { + return true; } $auth_user = null; return false; Index: pear-prepend.php =================================================================== --- pear-prepend.php (revision 312202) +++ pear-prepend.php (working copy) @@ -23,6 +23,7 @@ require_once "pear-manual.php"; } +session_start(); error_reporting(E_ALL); if ($_SERVER['SERVER_NAME'] != 'pecl.php.net') { @@ -86,16 +87,8 @@ auth_logout(); } -if (!empty($_COOKIE['PEAR_USER']) && !@auth_verify($_COOKIE['PEAR_USER'], $_COOKIE['PEAR_PW'])) { - $__user = $_COOKIE['PEAR_USER']; - setcookie('PEAR_USER', '', 0, '/'); - unset($_COOKIE['PEAR_USER']); - setcookie('PEAR_PW', '', 0, '/'); - unset($_COOKIE['PEAR_PW']); - $msg = "Invalid username ($__user) or password"; - if ($format == 'html') { - $msg .= " <a href=\"/?logout=1\">[logout]</a>"; - } +if (!empty($_COOKIE['PEAR_USER']) && !@auth_verify($_COOKIE['PEAR_USER'], @$_SESSION['credentials']['password'])) { + auth_logout(); auth_reject(null, $msg); } @@ -119,8 +112,6 @@ } } -session_start(); - /** * Browser detection */
« previous php.webmaster (#11294) next »