Michal Čihař
493ece49ee
Merge branch 'QA_4_6' into QA_4_6-security
2016-08-02 08:45:16 +02:00
Michal Čihař
38b73180fd
Fix password change in cookie auth
...
We can not set same cookie twice, so we have to avoid sending auth
cookie when we're about to change the password.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-08-02 08:42:44 +02:00
Michal Čihař
cc9d0f128c
Merge branch 'QA_4_6' into QA_4_6-security
2016-07-26 16:47:44 +02:00
Michal Čihař
16c4ca0daa
Properly escape configuration parameters when rendering
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-26 16:47:01 +02:00
Michal Čihař
76e87c3e33
Do not use mb_strlen on data we know are bytes
...
Issue #12397
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 16:39:12 +02:00
Michal Čihař
024a924b38
Avoid calculating strlen twice
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 14:12:45 +02:00
Michal Čihař
9106b33933
Improve secrets splitting
...
- ensure it has 16 bytes
- extends it by copying content if original is too short
- correctly handle corner cases (eg. 1 byte secret)
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 14:10:28 +02:00
Michal Čihař
643681ee68
Use consistent iv and encrypted text concatenation as other libs
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 13:46:51 +02:00
Michal Čihař
3ee65fc8bf
Use MAC to verify IV as well
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 10:29:46 +02:00
Michal Čihař
ef03daf658
Remove hashing of blowfish secret
...
New code doesn't have problems with longer secrets.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 09:59:02 +02:00
Michal Čihař
d29df46b3a
Do not generate too long session secret
...
We need 16+16 bytes, generating 256 is not really needed.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 09:58:39 +02:00
Michal Čihař
e2a25d773d
Merge pmaServer and pmaPass cookies
...
This addresses several issues:
- makes server name encrypted and authenticated, so that it can not be
tampered
- reduces cookie usage
- reduces overhead of encryption/authentication
The pmaUser cookie is still separate to avoid different lifetime
(pmaUser has month lifetime, while pmaAuth is session only by default).
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 09:47:32 +02:00
Michal Čihař
2a2d865d50
Validate input data from cookies
...
We expect strings only, so not accept anything else.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 09:47:32 +02:00
Michal Čihař
f45b8cd49c
Use different secret for MAC than encryption
...
Generated using string splitting.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-22 09:47:29 +02:00
Michal Čihař
3ba8a026fc
Use hash_hmac for MAC rather than plain SHA1
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-18 16:56:52 +02:00
Michal Čihař
3a4172525f
Merge branch 'QA_4_6' into QA_4_6-security
2016-07-18 15:56:38 +02:00
Michal Čihař
d35c3d9ed5
Update ReCaptcha library to 1.1.2
...
There should be no functional changes.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-18 15:51:44 +02:00
Michal Čihař
767195e197
Sanitize MySQL host name before connecting
...
It can contain p: prefix which we don't want to honor.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-12 15:14:57 +02:00
Michal Čihař
fc6ef261eb
Remove Swekey support
...
It is buggy and their servers are no longer working.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-11 09:02:58 +02:00
Michal Čihař
a97be3a604
Improve cookie encryption
...
- use MAC to validate content before decryption
- create unique IV for every cookie
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-07-08 17:40:05 +02:00
Michal Čihař
f978e347fb
Add missing requie once for testsuite
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-05-23 14:28:28 +02:00
Michal Čihař
f9d6c40939
Safer handling of sessions during authentication
...
- always generate new session for login form
- always generate new session when authenticated using cookie auth
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-05-23 13:48:25 +02:00
Michal Čihař
adfd5a22b9
Avoid double redirects in signon auth on logout
...
Also adjusts tests to no longer rely on runkit.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-05-23 13:23:16 +02:00
Michal Čihař
11eb574242
Improve handling of logout
...
- add separate script for handling logout
- no longer require old_usr for all authentication methods
(this avoids potential information leak)
- require valid token for logout
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-05-23 13:02:21 +02:00
Michal Čihař
21db724c85
Remove need for having define for test
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-05-23 12:09:36 +02:00
Michal Čihař
1523985bce
Fix login after logout with http authentication
...
We can not check token here as it's always there (in the URL) after
logout.
Fixes #12098
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-03-17 11:31:06 +01:00
Michal Čihař
5042b65398
Merge branch 'QA_4_5' into QA_4_6
2016-02-12 10:45:43 +01:00
Michal Čihař
4534a90b80
Silent warnings when checking for file existance
...
Another occurences of file_exists which can be limited by open_basedir.
Issue #11940
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-12 10:38:47 +01:00
Michal Čihař
2148e7cad8
Implement test for Cookie auth without runkit
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-03 20:21:40 +01:00
Michal Čihař
c2b41b829a
Wrap header() and headers_sent() in response
...
This allows us to test the code without using runkit. Currenly only
AuthenticationHttp is migrated to new code, but others will follow.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-03 19:49:05 +01:00
Michal Čihař
431450a237
Make test run even without runkit
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-03 19:49:05 +01:00
Michal Čihař
db6af1be82
Simplify code
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-03 17:57:19 +01:00
Michal Čihař
2a9fb73f92
Remove PmaAbsoluteUri from redirects
...
This is no longer needed as per RFC 7231.
Issue #11412
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-03 14:32:14 +01:00
Michal Čihař
ac9714cf6a
Autoloading for phpseclib
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-02-01 21:53:53 +01:00
Michal Čihař
7b58acf62e
Merge branch 'QA_4_5'
2016-02-01 21:46:33 +01:00
Madhura Jayaratne
30ac5b6094
Fix #11892 Error with PMA 4.4.15.3
...
Signed-off-by: Madhura Jayaratne <madhura.cj@gmail.com>
2016-01-29 08:33:42 +11:00
Michal Čihař
b69fa1499f
Bring back file inclustion, just remove version check from it
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-01-28 17:08:19 +01:00
Michal Čihař
072ff0b38a
Remove checks for PHP versions we no longer support
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-01-28 16:08:47 +01:00
Michal Čihař
37004337ab
Merge commit 'a478437e0ee4d74ec5036cb32e165da002303dd1'
2016-01-14 09:10:43 +01:00
Deven Bansod
3b8644318a
Fix #11752 , analyse the grant strings to perform checks for privileges instead of running all the test queries on mysql db
...
Signed-off-by: Deven Bansod <devenbansod.bits@gmail.com>
2016-01-08 16:48:57 +05:30
Michal Čihař
55b317c699
Remove /*overload*/ prefix from mb_* calls
...
I believe this was temporary flagging to see which code is migrated and
can be safely removed now.
Signed-off-by: Michal Čihař <michal@cihar.com>
2016-01-04 16:35:28 +01:00
Marc Delisle
66c15daba0
Remove some unnecessary string concatenations
...
https://github.com/dseguy/clearPHP/blob/master/rules/no-unnecessary-string-concatenation.md
Signed-off-by: Marc Delisle <marc@infomarc.info>
2015-12-06 08:01:07 -05:00
Marc Delisle
357b1b4757
Remove some unnecessary string concatenations
...
https://github.com/dseguy/clearPHP/blob/master/rules/no-unnecessary-string-concatenation.md
Signed-off-by: Marc Delisle <marc@infomarc.info>
2015-12-04 09:05:42 -05:00
Marc Delisle
2607023281
Remove some unnecessary string concatenations
...
https://github.com/dseguy/clearPHP/blob/master/rules/no-unnecessary-string-concatenation.md
Signed-off-by: Marc Delisle <marc@infomarc.info>
2015-12-03 11:00:01 -05:00
Marc Delisle
9ee3931c09
Remove some unnecessary string concatenations
...
https://github.com/dseguy/clearPHP/blob/master/rules/no-unnecessary-string-concatenation.md
Signed-off-by: Marc Delisle <marc@infomarc.info>
2015-12-03 10:43:10 -05:00
Michal Čihař
46a70dba88
Remove unused method (parent class defines it)
...
Signed-off-by: Michal Čihař <michal@cihar.com>
2015-12-01 13:54:04 +01:00
Marc Delisle
ab7942be89
Fix merge conflicts
...
Signed-off-by: Marc Delisle <marc@infomarc.info>
2015-11-29 07:29:32 -05:00
Deven Bansod
77f220cee5
Merge branch 'QA_4_5'
...
Signed-off-by: Deven Bansod <devenbansod.bits@gmail.com>
Conflicts:
libraries/plugins/auth/AuthenticationCookie.php
2015-11-26 19:29:18 +05:30
Deven Bansod
8eb712579d
Fixes #11693 : Flush privileges overusage - related to issue 11597
...
Signed-off-by: Deven Bansod <devenbansod.bits@gmail.com>
2015-11-26 19:25:18 +05:30
Hugues Peccatte
154a942145
Remove side effects in declaration files.
...
Signed-off-by: Hugues Peccatte <hugues.peccatte@gmail.com>
2015-10-27 18:56:40 +01:00