svn: /web/php-rmtools/trunk/ docroot/rm/login.php include/Auth.php

From: Date: Fri, 29 Jan 2010 09:55:10 +0000
Subject: svn: /web/php-rmtools/trunk/ docroot/rm/login.php include/Auth.php
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-7238@lists.php.net to get a copy of this message
pajoye Fri, 29 Jan 2010 09:55:10 +0000 Revision: http://svn.php.net/viewvc?view=revision&revision=294186 Log: - fix logic Changed paths: U web/php-rmtools/trunk/docroot/rm/login.php U web/php-rmtools/trunk/include/Auth.php Modified: web/php-rmtools/trunk/docroot/rm/login.php =================================================================== --- web/php-rmtools/trunk/docroot/rm/login.php 2010-01-29 09:50:41 UTC (rev 294185) +++ web/php-rmtools/trunk/docroot/rm/login.php 2010-01-29 09:55:10 UTC (rev 294186) @@ -5,40 +5,43 @@ session_name('_rmtools_'); session_start(); -if (!isset($_SESSION['username'])) { +if (1 ||!isset($_SESSION['username'])) { $username = $password = FALSE; if (isset($_POST['username'])) { $username = filter_input(INPUT_POST, 'username', FILTER_SANITIZE_STRING, FILTER_FLAG_STRIP_LOW|FILTER_FLAG_STRIP_HIGH); $password = filter_input(INPUT_POST, 'password', FILTER_SANITIZE_STRING, FILTER_FLAG_STRIP_LOW|FILTER_FLAG_STRIP_HIGH); - // Set magic cookie if login information is available - if ($password && $username) { - setcookie( - "MAGIC_COOKIE", - base64_encode("$username:$password"), - time()+3600*24*12, - '/', - '.php.net', - false, // Secure - true // HTTP Only - ); + } else { + // Preserve information previously set in magic cookie if available + if (isset($_COOKIE['MAGIC_COOKIE']) && !isset($_POST['user']) && !isset($_POST['pw'])) { + list($user, $password) = explode(":", base64_decode($_COOKIE['MAGIC_COOKIE']), 2); } } + $res = rm\Auth::login($username, $password); - // Preserve information previously set in magic cookie if available - if (isset($_COOKIE['MAGIC_COOKIE']) && !isset($_POST['user']) && !isset($_POST['pw'])) { - list($user, $password) = explode(":", base64_decode($_COOKIE['MAGIC_COOKIE']), 2); - } - - if (!$username || !$password || !rm\Auth::login($username, $password)) { + if (!$res) { $title = 'login'; include TPL_PATH . '/header.php'; include TPL_PATH . '/login.php'; include TPL_PATH . '/footer.php'; exit(); } + $_SESSION['username'] = $username; $_SESSION['time'] = time(); + + if ($password && $username) { + setcookie( + "MAGIC_COOKIE", + base64_encode("$username:$password"), + time()+3600*24*12, + '/', + '.php.net', + false, // Secure + true // HTTP Only + ); + } +} else { + $username = $_SESSION['username']; } -$username = $_SESSION['username']; Modified: web/php-rmtools/trunk/include/Auth.php =================================================================== --- web/php-rmtools/trunk/include/Auth.php 2010-01-29 09:50:41 UTC (rev 294185) +++ web/php-rmtools/trunk/include/Auth.php 2010-01-29 09:55:10 UTC (rev 294186) @@ -31,22 +31,23 @@ $ctx = stream_context_create(array("http" => $opts)); $s = file_get_contents("https://master.php.net/fetch/cvsauth.php", false, $ctx); if (!$s) { - return false; + return FALSE; } $a = unserialize($s); + /* define("E_UNKNOWN", 0); define("E_USERNAME", 1); define("E_PASSWORD", 2); */ if (!is_array($a)) { - return 0; + return FALSE; } if (isset($a["errno"])) { - return (int)$a["errno"]; + return FALSE; } - return true; + return TRUE; } }

« previous php.webmaster (#7238) next »