MDL-20934 'not cached' flag used in all auth plugins that do not need the password
This commit is contained in:
@@ -60,6 +60,11 @@ class auth_plugin_cas extends auth_plugin_base {
|
||||
$this->connectCAS();
|
||||
return phpCAS::isAuthenticated() && (trim(moodle_strtolower(phpCAS::getUser())) == $username);
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -564,6 +564,13 @@ class auth_plugin_db extends auth_plugin_base {
|
||||
}
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
if (!isset($this->config->passtype)) {
|
||||
return false;
|
||||
}
|
||||
return ($this->config->passtype != 'internal');
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -146,6 +146,10 @@ class auth_plugin_email extends auth_plugin_base {
|
||||
}
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -144,6 +144,10 @@ class auth_plugin_fc extends auth_plugin_base {
|
||||
return false;
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -81,6 +81,10 @@ class auth_plugin_imap extends auth_plugin_base {
|
||||
return false; // No match
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -1803,6 +1803,10 @@ class auth_plugin_ldap extends auth_plugin_base {
|
||||
return ($fresult);
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return !empty($this->config->preventpassindb);
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
if (!isset($config->opt_deref))
|
||||
{ $config->opt_deref = LDAP_DEREF_NEVER; }
|
||||
if (!isset($config->preventpassindb))
|
||||
{ $config->preventpassindb = 0; }
|
||||
{ $config->preventpassindb = 1; }
|
||||
if (!isset($config->bind_dn))
|
||||
{$config->bind_dn = ''; }
|
||||
if (!isset($config->bind_pw))
|
||||
|
||||
@@ -62,6 +62,10 @@ class auth_plugin_manual extends auth_plugin_base {
|
||||
return update_internal_user_password($user, $newpassword);
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -591,6 +591,10 @@ class auth_plugin_mnet extends auth_plugin_base {
|
||||
delete_records_select('mnet_enrol_assignments', $whereclause);
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -64,6 +64,10 @@ class auth_plugin_nntp extends auth_plugin_base {
|
||||
return false;
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -46,6 +46,11 @@ class auth_plugin_nologin extends auth_plugin_base {
|
||||
return false;
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
// just in case, we do not want to loose the passwords
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* No external data sync.
|
||||
*
|
||||
|
||||
@@ -62,6 +62,10 @@ class auth_plugin_none extends auth_plugin_base {
|
||||
return update_internal_user_password($user, $newpassword);
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -77,6 +77,10 @@ class auth_plugin_pam extends auth_plugin_base {
|
||||
}
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -81,6 +81,10 @@ class auth_plugin_pop3 extends auth_plugin_base {
|
||||
return false; // No matches found
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -126,6 +126,10 @@ class auth_plugin_radius extends auth_plugin_base {
|
||||
$rauth->close();
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -152,6 +152,10 @@ class auth_plugin_shibboleth extends auth_plugin_base {
|
||||
return $moodleattributes;
|
||||
}
|
||||
|
||||
function prevent_local_passwords() {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns true if this authentication plugin is 'internal'.
|
||||
*
|
||||
|
||||
@@ -2651,7 +2651,7 @@ define('RESTORE_GROUPS_GROUPINGS', 3);
|
||||
if (!array_key_exists($user->auth, $authcache)) { // Not in cache
|
||||
$userauth = new stdClass();
|
||||
$authplugin = get_auth_plugin($user->auth);
|
||||
$userauth->preventpassindb = !empty($authplugin->config->preventpassindb);
|
||||
$userauth->preventpassindb = $authplugin->prevent_local_passwords();
|
||||
$userauth->isinternal = $authplugin->is_internal();
|
||||
$userauth->canresetpwd = $authplugin->can_reset_password();
|
||||
$authcache[$user->auth] = $userauth;
|
||||
@@ -2659,7 +2659,7 @@ define('RESTORE_GROUPS_GROUPINGS', 3);
|
||||
$userauth = $authcache[$user->auth]; // Get from cache
|
||||
}
|
||||
|
||||
// Respect strange config in some (ldap) plugins. Isn't this a dupe of is_internal() ?
|
||||
// Most external plugins do not store passwords locally
|
||||
if (!empty($userauth->preventpassindb)) {
|
||||
$user->password = 'not cached';
|
||||
|
||||
|
||||
@@ -130,6 +130,15 @@ class auth_plugin_base {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Indicates if password hashes should be stored in local moodle database.
|
||||
* @return bool true means md5 password hash stored in user table, false means flag 'not_cached' stored there instead
|
||||
*/
|
||||
function prevent_local_passwords() {
|
||||
// NOTE: this will be changed to true in 2.0
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Updates the user's password. In previous versions of Moodle, the function
|
||||
* auth_user_update_password accepted a username as the first parameter. The
|
||||
|
||||
@@ -3273,6 +3273,23 @@ function xmldb_main_upgrade($oldversion=0) {
|
||||
upgrade_main_savepoint($result, 2007101563.02);
|
||||
}
|
||||
|
||||
if ($result && $oldversion < 2007101563.03) {
|
||||
// NOTE: this is quite hacky, but anyway it should work fine in 1.9,
|
||||
// in 2.0 we should always use plugin upgrade code for things like this
|
||||
|
||||
$authsavailable = get_list_of_plugins('auth');
|
||||
foreach($authsavailable as $authname) {
|
||||
if (!$auth = get_auth_plugin($authname)) {
|
||||
continue;
|
||||
}
|
||||
if ($auth->prevent_local_passwords()) {
|
||||
execute_sql("UPDATE {$CFG->prefix}user SET password='not cached' WHERE auth='$authname'");
|
||||
}
|
||||
}
|
||||
|
||||
upgrade_main_savepoint($result, 2007101563.03);
|
||||
}
|
||||
|
||||
return $result;
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -3381,7 +3381,7 @@ function update_internal_user_password(&$user, $password) {
|
||||
global $CFG;
|
||||
|
||||
$authplugin = get_auth_plugin($user->auth);
|
||||
if (!empty($authplugin->config->preventpassindb)) {
|
||||
if ($authplugin->prevent_local_passwords()) {
|
||||
$hashedpassword = 'not cached';
|
||||
} else {
|
||||
$hashedpassword = hash_internal_user_password($password);
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@
|
||||
// This is compared against the values stored in the database to determine
|
||||
// whether upgrades should be performed (see lib/db/*.php)
|
||||
|
||||
$version = 2007101563.02; // YYYYMMDD = date of the 1.9 branch (don't change)
|
||||
$version = 2007101563.03; // YYYYMMDD = date of the 1.9 branch (don't change)
|
||||
// X = release number 1.9.[0,1,2,3,4,5...]
|
||||
// Y.YY = micro-increments between releases
|
||||
|
||||
|
||||
Reference in New Issue
Block a user