diff --git a/auth/cas/auth.php b/auth/cas/auth.php index ee3e72a675f..856a3ee9525 100644 --- a/auth/cas/auth.php +++ b/auth/cas/auth.php @@ -60,6 +60,11 @@ class auth_plugin_cas extends auth_plugin_base { $this->connectCAS(); return phpCAS::isAuthenticated() && (trim(moodle_strtolower(phpCAS::getUser())) == $username); } + + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/db/auth.php b/auth/db/auth.php index 44d59e90a1e..7a859993249 100644 --- a/auth/db/auth.php +++ b/auth/db/auth.php @@ -564,6 +564,13 @@ class auth_plugin_db extends auth_plugin_base { } } + function prevent_local_passwords() { + if (!isset($this->config->passtype)) { + return false; + } + return ($this->config->passtype != 'internal'); + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/email/auth.php b/auth/email/auth.php index 732dc4dba16..a5e4f201335 100644 --- a/auth/email/auth.php +++ b/auth/email/auth.php @@ -146,6 +146,10 @@ class auth_plugin_email extends auth_plugin_base { } } + function prevent_local_passwords() { + return false; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/fc/auth.php b/auth/fc/auth.php index 9ef341b3521..95b87430f31 100644 --- a/auth/fc/auth.php +++ b/auth/fc/auth.php @@ -144,6 +144,10 @@ class auth_plugin_fc extends auth_plugin_base { return false; } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/imap/auth.php b/auth/imap/auth.php index c2c3cf0ae69..d5dda634535 100644 --- a/auth/imap/auth.php +++ b/auth/imap/auth.php @@ -81,6 +81,10 @@ class auth_plugin_imap extends auth_plugin_base { return false; // No match } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/ldap/auth.php b/auth/ldap/auth.php index dd05be6dbd7..bdec6a05777 100644 --- a/auth/ldap/auth.php +++ b/auth/ldap/auth.php @@ -1803,6 +1803,10 @@ class auth_plugin_ldap extends auth_plugin_base { return ($fresult); } + function prevent_local_passwords() { + return !empty($this->config->preventpassindb); + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/ldap/config.html b/auth/ldap/config.html index 52eb219f456..55ab6a7df5e 100644 --- a/auth/ldap/config.html +++ b/auth/ldap/config.html @@ -16,7 +16,7 @@ if (!isset($config->opt_deref)) { $config->opt_deref = LDAP_DEREF_NEVER; } if (!isset($config->preventpassindb)) - { $config->preventpassindb = 0; } + { $config->preventpassindb = 1; } if (!isset($config->bind_dn)) {$config->bind_dn = ''; } if (!isset($config->bind_pw)) diff --git a/auth/manual/auth.php b/auth/manual/auth.php index a8c469722f7..4ac157ec0cb 100644 --- a/auth/manual/auth.php +++ b/auth/manual/auth.php @@ -62,6 +62,10 @@ class auth_plugin_manual extends auth_plugin_base { return update_internal_user_password($user, $newpassword); } + function prevent_local_passwords() { + return false; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/mnet/auth.php b/auth/mnet/auth.php index 0542d9eb551..16a1d56244f 100644 --- a/auth/mnet/auth.php +++ b/auth/mnet/auth.php @@ -591,6 +591,10 @@ class auth_plugin_mnet extends auth_plugin_base { delete_records_select('mnet_enrol_assignments', $whereclause); } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/nntp/auth.php b/auth/nntp/auth.php index da549b915ea..8af71ce2307 100644 --- a/auth/nntp/auth.php +++ b/auth/nntp/auth.php @@ -64,6 +64,10 @@ class auth_plugin_nntp extends auth_plugin_base { return false; } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/nologin/auth.php b/auth/nologin/auth.php index 91070593673..740a68153d5 100644 --- a/auth/nologin/auth.php +++ b/auth/nologin/auth.php @@ -46,6 +46,11 @@ class auth_plugin_nologin extends auth_plugin_base { return false; } + function prevent_local_passwords() { + // just in case, we do not want to loose the passwords + return false; + } + /** * No external data sync. * diff --git a/auth/none/auth.php b/auth/none/auth.php index 9b2da1e04b1..f53af38003e 100644 --- a/auth/none/auth.php +++ b/auth/none/auth.php @@ -62,6 +62,10 @@ class auth_plugin_none extends auth_plugin_base { return update_internal_user_password($user, $newpassword); } + function prevent_local_passwords() { + return false; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/pam/auth.php b/auth/pam/auth.php index 94a179eb299..48c9aa0fbe6 100644 --- a/auth/pam/auth.php +++ b/auth/pam/auth.php @@ -77,6 +77,10 @@ class auth_plugin_pam extends auth_plugin_base { } } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/pop3/auth.php b/auth/pop3/auth.php index 888b0d62965..6f52fee43b7 100644 --- a/auth/pop3/auth.php +++ b/auth/pop3/auth.php @@ -81,6 +81,10 @@ class auth_plugin_pop3 extends auth_plugin_base { return false; // No matches found } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/radius/auth.php b/auth/radius/auth.php index 6855925d501..ef8c288b006 100644 --- a/auth/radius/auth.php +++ b/auth/radius/auth.php @@ -126,6 +126,10 @@ class auth_plugin_radius extends auth_plugin_base { $rauth->close(); } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/auth/shibboleth/auth.php b/auth/shibboleth/auth.php index 9fcfdbf7807..fd2e5cac667 100644 --- a/auth/shibboleth/auth.php +++ b/auth/shibboleth/auth.php @@ -152,6 +152,10 @@ class auth_plugin_shibboleth extends auth_plugin_base { return $moodleattributes; } + function prevent_local_passwords() { + return true; + } + /** * Returns true if this authentication plugin is 'internal'. * diff --git a/backup/restorelib.php b/backup/restorelib.php index df38898d1b0..a0e9fa0dca3 100644 --- a/backup/restorelib.php +++ b/backup/restorelib.php @@ -2651,7 +2651,7 @@ define('RESTORE_GROUPS_GROUPINGS', 3); if (!array_key_exists($user->auth, $authcache)) { // Not in cache $userauth = new stdClass(); $authplugin = get_auth_plugin($user->auth); - $userauth->preventpassindb = !empty($authplugin->config->preventpassindb); + $userauth->preventpassindb = $authplugin->prevent_local_passwords(); $userauth->isinternal = $authplugin->is_internal(); $userauth->canresetpwd = $authplugin->can_reset_password(); $authcache[$user->auth] = $userauth; @@ -2659,7 +2659,7 @@ define('RESTORE_GROUPS_GROUPINGS', 3); $userauth = $authcache[$user->auth]; // Get from cache } - // Respect strange config in some (ldap) plugins. Isn't this a dupe of is_internal() ? + // Most external plugins do not store passwords locally if (!empty($userauth->preventpassindb)) { $user->password = 'not cached'; diff --git a/lib/authlib.php b/lib/authlib.php index b45e81fe072..076242ad5b7 100644 --- a/lib/authlib.php +++ b/lib/authlib.php @@ -130,6 +130,15 @@ class auth_plugin_base { return true; } + /** + * Indicates if password hashes should be stored in local moodle database. + * @return bool true means md5 password hash stored in user table, false means flag 'not_cached' stored there instead + */ + function prevent_local_passwords() { + // NOTE: this will be changed to true in 2.0 + return false; + } + /** * Updates the user's password. In previous versions of Moodle, the function * auth_user_update_password accepted a username as the first parameter. The diff --git a/lib/db/upgrade.php b/lib/db/upgrade.php index 7ca4bc580d7..32d7f09afa4 100644 --- a/lib/db/upgrade.php +++ b/lib/db/upgrade.php @@ -3273,6 +3273,23 @@ function xmldb_main_upgrade($oldversion=0) { upgrade_main_savepoint($result, 2007101563.02); } + if ($result && $oldversion < 2007101563.03) { + // NOTE: this is quite hacky, but anyway it should work fine in 1.9, + // in 2.0 we should always use plugin upgrade code for things like this + + $authsavailable = get_list_of_plugins('auth'); + foreach($authsavailable as $authname) { + if (!$auth = get_auth_plugin($authname)) { + continue; + } + if ($auth->prevent_local_passwords()) { + execute_sql("UPDATE {$CFG->prefix}user SET password='not cached' WHERE auth='$authname'"); + } + } + + upgrade_main_savepoint($result, 2007101563.03); + } + return $result; } diff --git a/lib/moodlelib.php b/lib/moodlelib.php index 88cd5ee0ab4..18038da47e9 100644 --- a/lib/moodlelib.php +++ b/lib/moodlelib.php @@ -3381,7 +3381,7 @@ function update_internal_user_password(&$user, $password) { global $CFG; $authplugin = get_auth_plugin($user->auth); - if (!empty($authplugin->config->preventpassindb)) { + if ($authplugin->prevent_local_passwords()) { $hashedpassword = 'not cached'; } else { $hashedpassword = hash_internal_user_password($password); diff --git a/version.php b/version.php index c4b5fa5e3d8..f59d98cb705 100644 --- a/version.php +++ b/version.php @@ -6,7 +6,7 @@ // This is compared against the values stored in the database to determine // whether upgrades should be performed (see lib/db/*.php) - $version = 2007101563.02; // YYYYMMDD = date of the 1.9 branch (don't change) + $version = 2007101563.03; // YYYYMMDD = date of the 1.9 branch (don't change) // X = release number 1.9.[0,1,2,3,4,5...] // Y.YY = micro-increments between releases