Home » Authentication » LiveUser » Bug #6551
Secret key in conf.php not taken into account
Details
| Submitted | 2006-01-22 18:54 UTC |
|---|---|
| From | goethals_d at hotmail dot com |
| Assigned | lsmith |
| Status | Closed |
| Package | LiveUser |
| PHP Version | 5.0.4 |
| OS | WXP |
| Roadmaps | (Not assigned) |
Comments
[2006-01-22 18:54 UTC] goethals_d at hotmail dot com
Description:
------------
Set encryption mode to RC4 in configuration file.
If the secret key is set to 'test', I can login. If I modify the secret key to 'word' without changing the DB contents, I can still login.
Note that the password encrypted with LiveUser::Crypt_RC4 or the password encrypted with PEAR::Crypt_RC4 using the same secret key do not match.
Test script:
---------------
conf.php
...
'authContainers' => array(
array(
'type' => 'MDB2',
'expireTime' => 3600,
'idleTime' => 1800,
'allowDuplicateHandles' => 0,
'allowEmptyPasswords' => 0,
'passwordEncryptionMode'=> 'RC4',
'secret' => 'test',
...