Skip to content
GitLab
Projects
Groups
Snippets
/
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in
Toggle navigation
Menu
Open sidebar
Wolfgang Knopki
simplesamlphp_sqlauthbcrypt
Commits
afc9f4da
Commit
afc9f4da
authored
12 years ago
by
chris.lewis
Browse files
Options
Download
Email Patches
Plain Diff
removed separate salt. Salt is contained inside the main hash
parent
19cb2f94
Changes
1
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
lib/Auth/Source/SQL.php
+3
-12
lib/Auth/Source/SQL.php
with
3 additions
and
12 deletions
+3
-12
lib/Auth/Source/SQL.php
+
3
-
12
View file @
afc9f4da
...
@@ -52,13 +52,6 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
...
@@ -52,13 +52,6 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
*/
*/
private
$hash_column
;
private
$hash_column
;
/**
* The column holding the password salt.
*/
private
$salt_column
;
/**
/**
* Constructor for this authentication source.
* Constructor for this authentication source.
*
*
...
@@ -93,7 +86,6 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
...
@@ -93,7 +86,6 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
$this
->
query
=
$config
[
'query'
];
$this
->
query
=
$config
[
'query'
];
$this
->
pepper
=
$config
[
'pepper'
];
$this
->
pepper
=
$config
[
'pepper'
];
$this
->
hash_column
=
$config
[
'hash_column'
];
$this
->
hash_column
=
$config
[
'hash_column'
];
$this
->
salt_column
=
$config
[
'salt_column'
];
}
}
...
@@ -184,9 +176,8 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
...
@@ -184,9 +176,8 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
/* Validate stored password hash (must be in first row of resultset) */
/* Validate stored password hash (must be in first row of resultset) */
$password_hash
=
$data
[
0
][
$this
->
hash_column
];
$password_hash
=
$data
[
0
][
$this
->
hash_column
];
$password_salt
=
$data
[
0
][
$this
->
salt_column
];
if
(
$password_hash
!==
crypt
(
$password
.
$this
->
pepper
,
$password_
salt
))
{
if
(
$password_hash
!==
crypt
(
$password
.
$this
->
pepper
,
$password_
hash
))
{
/* Invalid password */
/* Invalid password */
SimpleSAML_Logger
::
error
(
'sqlauthBcrypt:'
.
$this
->
authId
.
SimpleSAML_Logger
::
error
(
'sqlauthBcrypt:'
.
$this
->
authId
.
': Hash does not match. Wrong password or sqlauthBcrypt is misconfigured.'
);
': Hash does not match. Wrong password or sqlauthBcrypt is misconfigured.'
);
...
@@ -205,8 +196,8 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
...
@@ -205,8 +196,8 @@ class sspmod_sqlauthBcrypt_Auth_Source_SQL extends sspmod_core_Auth_UserPassBase
continue
;
continue
;
}
}
if
(
$name
===
$this
->
hash_column
||
$name
===
$this
->
salt_column
)
{
if
(
$name
===
$this
->
hash_column
)
{
/* Don't add password hash
and salt
to attributes */
/* Don't add password hash to attributes */
continue
;
continue
;
}
}
...
...
This diff is collapsed.
Click to expand it.
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment