From d9468e3fff383c61fa7ab1649978b161d7ab83ec Mon Sep 17 00:00:00 2001 From: Robert Scheck Date: Sun, 7 Dec 2014 06:37:15 -0500 Subject: [PATCH] Bug #4623 Incomplete PHP OpenSSL support Signed-off-by: Marc Delisle --- .../plugins/auth/AuthenticationCookie.class.php | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/libraries/plugins/auth/AuthenticationCookie.class.php b/libraries/plugins/auth/AuthenticationCookie.class.php index 9f67209da0..c9012486fb 100644 --- a/libraries/plugins/auth/AuthenticationCookie.class.php +++ b/libraries/plugins/auth/AuthenticationCookie.class.php @@ -31,8 +31,13 @@ require './libraries/plugins/auth/swekey/swekey.auth.lib.php'; /** * phpseclib */ -require PHPSECLIB_INC_DIR . '/Crypt/AES.php'; -require PHPSECLIB_INC_DIR . '/Crypt/Random.php'; +if (! function_exists('openssl_encrypt') + || ! function_exists('openssl_decrypt') + || ! function_exists('openssl_random_pseudo_bytes') + || PHP_VERSION_ID < 50304) { + require PHPSECLIB_INC_DIR . '/Crypt/AES.php'; + require PHPSECLIB_INC_DIR . '/Crypt/Random.php'; +} /** * Handles the cookie authentication method @@ -728,7 +733,11 @@ class AuthenticationCookie extends AuthenticationPlugin private function _getSessionEncryptionSecret() { if (empty($_SESSION['encryption_key'])) { - $_SESSION['encryption_key'] = crypt_random_string(256); + if ($this->_useOpenSSL()) { + $_SESSION['encryption_key'] = openssl_random_pseudo_bytes(256); + } else { + $_SESSION['encryption_key'] = crypt_random_string(256); + } } return $_SESSION['encryption_key']; } @@ -743,6 +752,7 @@ class AuthenticationCookie extends AuthenticationPlugin return ( function_exists('openssl_encrypt') && function_exists('openssl_decrypt') + && function_exists('openssl_random_pseudo_bytes') && PHP_VERSION_ID >= 50304 ); }