@@ -57,29 +57,29 @@ discard block |
||
| 57 | 57 | */ |
| 58 | 58 | $domain = ! empty($_SERVER['HTTP_HOST']) ? strtolower($_SERVER['HTTP_HOST']) : 'cli'; |
| 59 | 59 | |
| 60 | - /** |
|
| 61 | - * A simple method to automatically determine the environment that |
|
| 62 | - * the script is running on. Modify to support your needs. |
|
| 63 | - * |
|
| 64 | - * To handle Travis-ci testing, we check for an environment |
|
| 65 | - * variable called TRAVIS which is set in the .travis.yml file. |
|
| 66 | - * This allows a database-specific setup for Travis testing. |
|
| 67 | - */ |
|
| 68 | - if (isset($_ENV['TRAVIS'])) |
|
| 69 | - { |
|
| 70 | - define('ENVIRONMENT', 'travis'); |
|
| 71 | - } |
|
| 72 | - else if (isset($_ENV['TESTING'])) |
|
| 73 | - { |
|
| 74 | - define('ENVIRONMENT', 'testing'); |
|
| 75 | - } |
|
| 76 | - else if (strpos($domain, '.dev') !== false || $domain == 'cli') |
|
| 77 | - { |
|
| 78 | - define('ENVIRONMENT', 'development'); |
|
| 79 | - } |
|
| 80 | - else { |
|
| 81 | - define('ENVIRONMENT', 'production'); |
|
| 82 | - } |
|
| 60 | + /** |
|
| 61 | + * A simple method to automatically determine the environment that |
|
| 62 | + * the script is running on. Modify to support your needs. |
|
| 63 | + * |
|
| 64 | + * To handle Travis-ci testing, we check for an environment |
|
| 65 | + * variable called TRAVIS which is set in the .travis.yml file. |
|
| 66 | + * This allows a database-specific setup for Travis testing. |
|
| 67 | + */ |
|
| 68 | + if (isset($_ENV['TRAVIS'])) |
|
| 69 | + { |
|
| 70 | + define('ENVIRONMENT', 'travis'); |
|
| 71 | + } |
|
| 72 | + else if (isset($_ENV['TESTING'])) |
|
| 73 | + { |
|
| 74 | + define('ENVIRONMENT', 'testing'); |
|
| 75 | + } |
|
| 76 | + else if (strpos($domain, '.dev') !== false || $domain == 'cli') |
|
| 77 | + { |
|
| 78 | + define('ENVIRONMENT', 'development'); |
|
| 79 | + } |
|
| 80 | + else { |
|
| 81 | + define('ENVIRONMENT', 'production'); |
|
| 82 | + } |
|
| 83 | 83 | |
| 84 | 84 | /* |
| 85 | 85 | *--------------------------------------------------------------- |
@@ -92,7 +92,7 @@ discard block |
||
| 92 | 92 | switch (ENVIRONMENT) |
| 93 | 93 | { |
| 94 | 94 | case 'development': |
| 95 | - case 'travis': |
|
| 95 | + case 'travis': |
|
| 96 | 96 | case 'testing': |
| 97 | 97 | error_reporting(-1); |
| 98 | 98 | ini_set('display_errors', 1); |
@@ -150,7 +150,7 @@ discard block |
||
| 150 | 150 | * Include the path if the folder is not in the same directory |
| 151 | 151 | * as this file. |
| 152 | 152 | */ |
| 153 | - $myth_folder = 'myth'; |
|
| 153 | + $myth_folder = 'myth'; |
|
| 154 | 154 | |
| 155 | 155 | /* |
| 156 | 156 | *--------------------------------------------------------------- |
@@ -267,8 +267,8 @@ discard block |
||
| 267 | 267 | // Name of the "system folder" |
| 268 | 268 | define('SYSDIR', trim(strrchr(trim(BASEPATH, '/'), '/'), '/')); |
| 269 | 269 | |
| 270 | - // Path to the myth folder |
|
| 271 | - define('MYTHPATH', rtrim( str_replace('\\', '/', $myth_folder), '/ ') .'/' ); |
|
| 270 | + // Path to the myth folder |
|
| 271 | + define('MYTHPATH', rtrim( str_replace('\\', '/', $myth_folder), '/ ') .'/' ); |
|
| 272 | 272 | |
| 273 | 273 | // The path to the "application" folder |
| 274 | 274 | if (is_dir($application_folder)) |
@@ -74,7 +74,7 @@ discard block |
||
| 74 | 74 | */ |
| 75 | 75 | public function setRealm($realm) |
| 76 | 76 | { |
| 77 | - $this->realm = $realm; |
|
| 77 | + $this->realm = $realm; |
|
| 78 | 78 | return $this; |
| 79 | 79 | } |
| 80 | 80 | |
@@ -116,7 +116,7 @@ discard block |
||
| 116 | 116 | 'password' => $password |
| 117 | 117 | ]; |
| 118 | 118 | |
| 119 | - $user = $this->validate($data, true); |
|
| 119 | + $user = $this->validate($data, true); |
|
| 120 | 120 | |
| 121 | 121 | $this->user = $user; |
| 122 | 122 | |
@@ -272,7 +272,7 @@ discard block |
||
| 272 | 272 | */ |
| 273 | 273 | public function checkIPBlacklist() |
| 274 | 274 | { |
| 275 | - $blacklist = explode(',', config_item('api.ip_blacklist')); |
|
| 275 | + $blacklist = explode(',', config_item('api.ip_blacklist')); |
|
| 276 | 276 | |
| 277 | 277 | array_walk($blacklist, function (&$item, $key) { |
| 278 | 278 | $item = trim($item); |
@@ -141,8 +141,8 @@ discard block |
||
| 141 | 141 | * @var array |
| 142 | 142 | */ |
| 143 | 143 | protected $codes = array( |
| 144 | - 'created' => 201, |
|
| 145 | - 'deleted' => 200, |
|
| 144 | + 'created' => 201, |
|
| 145 | + 'deleted' => 200, |
|
| 146 | 146 | 'invalid_request' => 400, |
| 147 | 147 | 'unsupported_response_type' => 400, |
| 148 | 148 | 'invalid_scope' => 400, |
@@ -166,32 +166,32 @@ discard block |
||
| 166 | 166 | 'not_implemented' => 501 |
| 167 | 167 | ); |
| 168 | 168 | |
| 169 | - /** |
|
| 170 | - * Convert common browser-sent langauge |
|
| 171 | - * strings to a folder name in the languages folder |
|
| 172 | - * that we want to use. |
|
| 173 | - * |
|
| 174 | - * Primarily used for converting to english when |
|
| 175 | - * viewing the API in a browser. |
|
| 176 | - * |
|
| 177 | - * @var array |
|
| 178 | - */ |
|
| 179 | - protected $lang_map = [ |
|
| 180 | - 'en-us' => 'english', |
|
| 181 | - 'en' => 'english', |
|
| 182 | - 'eng' => 'english', |
|
| 183 | - 'en-au' => 'english', |
|
| 184 | - 'en-nz' => 'english', |
|
| 185 | - 'en-za' => 'english', |
|
| 186 | - 'en-tt' => 'english', |
|
| 187 | - 'en-gb' => 'english', |
|
| 188 | - 'en-ca' => 'english', |
|
| 189 | - 'en-ie' => 'english', |
|
| 190 | - 'en-jm' => 'english', |
|
| 191 | - 'en-bz' => 'english', |
|
| 192 | - ]; |
|
| 193 | - |
|
| 194 | - /** |
|
| 169 | + /** |
|
| 170 | + * Convert common browser-sent langauge |
|
| 171 | + * strings to a folder name in the languages folder |
|
| 172 | + * that we want to use. |
|
| 173 | + * |
|
| 174 | + * Primarily used for converting to english when |
|
| 175 | + * viewing the API in a browser. |
|
| 176 | + * |
|
| 177 | + * @var array |
|
| 178 | + */ |
|
| 179 | + protected $lang_map = [ |
|
| 180 | + 'en-us' => 'english', |
|
| 181 | + 'en' => 'english', |
|
| 182 | + 'eng' => 'english', |
|
| 183 | + 'en-au' => 'english', |
|
| 184 | + 'en-nz' => 'english', |
|
| 185 | + 'en-za' => 'english', |
|
| 186 | + 'en-tt' => 'english', |
|
| 187 | + 'en-gb' => 'english', |
|
| 188 | + 'en-ca' => 'english', |
|
| 189 | + 'en-ie' => 'english', |
|
| 190 | + 'en-jm' => 'english', |
|
| 191 | + 'en-bz' => 'english', |
|
| 192 | + ]; |
|
| 193 | + |
|
| 194 | + /** |
|
| 195 | 195 | * If you wish to override the default authentication |
| 196 | 196 | * library used for authentication, set this to the |
| 197 | 197 | * fully namespaced class name. |
@@ -544,7 +544,7 @@ discard block |
||
| 544 | 544 | */ |
| 545 | 545 | public function grabVar($name) |
| 546 | 546 | { |
| 547 | - return array_key_exists($name, $this->vars) ? $this->vars[$name] : false; |
|
| 547 | + return array_key_exists($name, $this->vars) ? $this->vars[$name] : false; |
|
| 548 | 548 | } |
| 549 | 549 | |
| 550 | 550 | //-------------------------------------------------------------------- |
@@ -757,12 +757,12 @@ discard block |
||
| 757 | 757 | // Remove weight and strip space |
| 758 | 758 | list($lang) = explode(';', $lang); |
| 759 | 759 | |
| 760 | - $lang = strtolower(trim($lang)); |
|
| 760 | + $lang = strtolower(trim($lang)); |
|
| 761 | 761 | |
| 762 | - if (array_key_exists($lang, $this->lang_map)) |
|
| 763 | - { |
|
| 764 | - $lang = $this->lang_map[$lang]; |
|
| 765 | - } |
|
| 762 | + if (array_key_exists($lang, $this->lang_map)) |
|
| 763 | + { |
|
| 764 | + $lang = $this->lang_map[$lang]; |
|
| 765 | + } |
|
| 766 | 766 | |
| 767 | 767 | $return_langs[] = $lang; |
| 768 | 768 | } |
@@ -782,10 +782,10 @@ discard block |
||
| 782 | 782 | */ |
| 783 | 783 | public function detectFields() |
| 784 | 784 | { |
| 785 | - if (! array_key_exists('fields', $_GET)) |
|
| 786 | - { |
|
| 787 | - return; |
|
| 788 | - } |
|
| 785 | + if (! array_key_exists('fields', $_GET)) |
|
| 786 | + { |
|
| 787 | + return; |
|
| 788 | + } |
|
| 789 | 789 | |
| 790 | 790 | $fields = explode(',', $_GET['fields']); |
| 791 | 791 | |
@@ -814,7 +814,7 @@ discard block |
||
| 814 | 814 | return; |
| 815 | 815 | } |
| 816 | 816 | |
| 817 | - $model = new LogModel(); |
|
| 817 | + $model = new LogModel(); |
|
| 818 | 818 | |
| 819 | 819 | $data = [ |
| 820 | 820 | 'duration' => microtime(true) - $this->start_time, |
@@ -1,34 +1,34 @@ discard block |
||
| 1 | 1 | <?php namespace Myth\Auth; |
| 2 | 2 | /** |
| 3 | - * Sprint |
|
| 4 | - * |
|
| 5 | - * A set of power tools to enhance the CodeIgniter framework and provide consistent workflow. |
|
| 6 | - * |
|
| 7 | - * Permission is hereby granted, free of charge, to any person obtaining a copy |
|
| 8 | - * of this software and associated documentation files (the "Software"), to deal |
|
| 9 | - * in the Software without restriction, including without limitation the rights |
|
| 10 | - * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|
| 11 | - * copies of the Software, and to permit persons to whom the Software is |
|
| 12 | - * furnished to do so, subject to the following conditions: |
|
| 13 | - * |
|
| 14 | - * The above copyright notice and this permission notice shall be included in |
|
| 15 | - * all copies or substantial portions of the Software. |
|
| 16 | - * |
|
| 17 | - * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|
| 18 | - * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|
| 19 | - * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|
| 20 | - * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|
| 21 | - * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|
| 22 | - * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN |
|
| 23 | - * THE SOFTWARE. |
|
| 24 | - * |
|
| 25 | - * @package Sprint |
|
| 26 | - * @author Lonnie Ezell |
|
| 27 | - * @copyright Copyright 2014-2015, New Myth Media, LLC (http://newmythmedia.com) |
|
| 28 | - * @license http://opensource.org/licenses/MIT (MIT) |
|
| 29 | - * @link http://sprintphp.com |
|
| 30 | - * @since Version 1.0 |
|
| 31 | - */ |
|
| 3 | + * Sprint |
|
| 4 | + * |
|
| 5 | + * A set of power tools to enhance the CodeIgniter framework and provide consistent workflow. |
|
| 6 | + * |
|
| 7 | + * Permission is hereby granted, free of charge, to any person obtaining a copy |
|
| 8 | + * of this software and associated documentation files (the "Software"), to deal |
|
| 9 | + * in the Software without restriction, including without limitation the rights |
|
| 10 | + * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|
| 11 | + * copies of the Software, and to permit persons to whom the Software is |
|
| 12 | + * furnished to do so, subject to the following conditions: |
|
| 13 | + * |
|
| 14 | + * The above copyright notice and this permission notice shall be included in |
|
| 15 | + * all copies or substantial portions of the Software. |
|
| 16 | + * |
|
| 17 | + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|
| 18 | + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|
| 19 | + * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|
| 20 | + * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|
| 21 | + * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|
| 22 | + * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN |
|
| 23 | + * THE SOFTWARE. |
|
| 24 | + * |
|
| 25 | + * @package Sprint |
|
| 26 | + * @author Lonnie Ezell |
|
| 27 | + * @copyright Copyright 2014-2015, New Myth Media, LLC (http://newmythmedia.com) |
|
| 28 | + * @license http://opensource.org/licenses/MIT (MIT) |
|
| 29 | + * @link http://sprintphp.com |
|
| 30 | + * @since Version 1.0 |
|
| 31 | + */ |
|
| 32 | 32 | |
| 33 | 33 | trait AuthTrait { |
| 34 | 34 | |
@@ -58,7 +58,7 @@ discard block |
||
| 58 | 58 | */ |
| 59 | 59 | public function restrict($uri=null, $return_only=false) |
| 60 | 60 | { |
| 61 | - $this->setupAuthClasses(); |
|
| 61 | + $this->setupAuthClasses(); |
|
| 62 | 62 | |
| 63 | 63 | if ($this->authenticate->isLoggedIn()) |
| 64 | 64 | { |
@@ -108,7 +108,7 @@ discard block |
||
| 108 | 108 | */ |
| 109 | 109 | public function restrictToGroups($groups, $uri='') |
| 110 | 110 | { |
| 111 | - $this->setupAuthClasses(); |
|
| 111 | + $this->setupAuthClasses(); |
|
| 112 | 112 | |
| 113 | 113 | if ($this->authenticate->isLoggedIn()) |
| 114 | 114 | { |
@@ -149,7 +149,7 @@ discard block |
||
| 149 | 149 | */ |
| 150 | 150 | public function restrictWithPermissions($permissions, $uri='') |
| 151 | 151 | { |
| 152 | - $this->setupAuthClasses(); |
|
| 152 | + $this->setupAuthClasses(); |
|
| 153 | 153 | |
| 154 | 154 | if ($this->authenticate->isLoggedIn()) |
| 155 | 155 | { |
@@ -85,10 +85,10 @@ discard block |
||
| 85 | 85 | */ |
| 86 | 86 | public function addUserToGroup($user_id, $group_id) |
| 87 | 87 | { |
| 88 | - $data = [ |
|
| 89 | - 'user_id' => (int)$user_id, |
|
| 90 | - 'group_id' => (int)$group_id |
|
| 91 | - ]; |
|
| 88 | + $data = [ |
|
| 89 | + 'user_id' => (int)$user_id, |
|
| 90 | + 'group_id' => (int)$group_id |
|
| 91 | + ]; |
|
| 92 | 92 | |
| 93 | 93 | return $this->db->insert('auth_groups_users', $data); |
| 94 | 94 | } |
@@ -105,10 +105,10 @@ discard block |
||
| 105 | 105 | */ |
| 106 | 106 | public function removeUserFromGroup($user_id, $group_id) |
| 107 | 107 | { |
| 108 | - return $this->where([ |
|
| 109 | - 'user_id' => (int)$user_id, |
|
| 110 | - 'group_id' => (int)$group_id |
|
| 111 | - ])->delete('auth_groups_users'); |
|
| 108 | + return $this->where([ |
|
| 109 | + 'user_id' => (int)$user_id, |
|
| 110 | + 'group_id' => (int)$group_id |
|
| 111 | + ])->delete('auth_groups_users'); |
|
| 112 | 112 | } |
| 113 | 113 | |
| 114 | 114 | //-------------------------------------------------------------------- |
@@ -122,8 +122,8 @@ discard block |
||
| 122 | 122 | */ |
| 123 | 123 | public function removeUserFromAllGroups($user_id) |
| 124 | 124 | { |
| 125 | - return $this->db->where('user_id', (int)$user_id) |
|
| 126 | - ->delete('auth_groups_users'); |
|
| 125 | + return $this->db->where('user_id', (int)$user_id) |
|
| 126 | + ->delete('auth_groups_users'); |
|
| 127 | 127 | } |
| 128 | 128 | |
| 129 | 129 | //-------------------------------------------------------------------- |
@@ -137,11 +137,11 @@ discard block |
||
| 137 | 137 | */ |
| 138 | 138 | public function getGroupsForUser($user_id) |
| 139 | 139 | { |
| 140 | - return $this->select('auth_groups_users.*, auth_groups.name, auth_groups.description') |
|
| 141 | - ->join('auth_groups_users', 'auth_groups_users.group_id = auth_groups.id', 'left') |
|
| 142 | - ->where('user_id', $user_id) |
|
| 143 | - ->as_array() |
|
| 144 | - ->find_all(); |
|
| 140 | + return $this->select('auth_groups_users.*, auth_groups.name, auth_groups.description') |
|
| 141 | + ->join('auth_groups_users', 'auth_groups_users.group_id = auth_groups.id', 'left') |
|
| 142 | + ->where('user_id', $user_id) |
|
| 143 | + ->as_array() |
|
| 144 | + ->find_all(); |
|
| 145 | 145 | } |
| 146 | 146 | |
| 147 | 147 | //-------------------------------------------------------------------- |
@@ -160,7 +160,7 @@ discard block |
||
| 160 | 160 | 'group_id' => (int)$group_id |
| 161 | 161 | ]; |
| 162 | 162 | |
| 163 | - return $this->db->insert('auth_groups_permissions', $data); |
|
| 163 | + return $this->db->insert('auth_groups_permissions', $data); |
|
| 164 | 164 | } |
| 165 | 165 | |
| 166 | 166 | //-------------------------------------------------------------------- |
@@ -176,10 +176,10 @@ discard block |
||
| 176 | 176 | */ |
| 177 | 177 | public function removePermissionFromGroup($permission_id, $group_id) |
| 178 | 178 | { |
| 179 | - return $this->db->where([ |
|
| 180 | - 'permission_id' => $permission_id, |
|
| 181 | - 'group_id' => $group_id |
|
| 182 | - ])->delete('auth_groups_permissions'); |
|
| 179 | + return $this->db->where([ |
|
| 180 | + 'permission_id' => $permission_id, |
|
| 181 | + 'group_id' => $group_id |
|
| 182 | + ])->delete('auth_groups_permissions'); |
|
| 183 | 183 | } |
| 184 | 184 | |
| 185 | 185 | //-------------------------------------------------------------------- |
@@ -193,8 +193,8 @@ discard block |
||
| 193 | 193 | */ |
| 194 | 194 | public function removePermissionFromAllGroups($permission_id) |
| 195 | 195 | { |
| 196 | - return $this->db->where('permission_id', $permission_id) |
|
| 197 | - ->delete('auth_groups_permissions'); |
|
| 196 | + return $this->db->where('permission_id', $permission_id) |
|
| 197 | + ->delete('auth_groups_permissions'); |
|
| 198 | 198 | } |
| 199 | 199 | |
| 200 | 200 | //-------------------------------------------------------------------- |
@@ -51,325 +51,325 @@ |
||
| 51 | 51 | */ |
| 52 | 52 | class Password { |
| 53 | 53 | |
| 54 | - /** |
|
| 55 | - * A standardized method for hasing a password before storing |
|
| 56 | - * in the database. |
|
| 57 | - * |
|
| 58 | - * @param $password |
|
| 59 | - * @return bool|mixed|string |
|
| 60 | - */ |
|
| 61 | - public static function hashPassword($password) |
|
| 62 | - { |
|
| 63 | - if (! config_item('auth.hash_cost')) |
|
| 64 | - { |
|
| 65 | - get_instance()->load->config('auth'); |
|
| 66 | - } |
|
| 67 | - |
|
| 68 | - return password_hash($password, PASSWORD_DEFAULT, ['cost' => config_item('auth.hash_cost')]); |
|
| 69 | - } |
|
| 70 | - |
|
| 71 | - //-------------------------------------------------------------------- |
|
| 72 | - |
|
| 73 | - /** |
|
| 74 | - * Determines the number of entropy bits a password has based on |
|
| 75 | - * |
|
| 76 | - * |
|
| 77 | - * @param $password |
|
| 78 | - * @param bool $repeatcalc |
|
| 79 | - * @return int |
|
| 80 | - */ |
|
| 81 | - public static function getNISTNumBits($password, $repeatcalc = false) |
|
| 82 | - { |
|
| 83 | - $y = strlen($password); |
|
| 84 | - if ($repeatcalc) |
|
| 85 | - { |
|
| 86 | - // Variant on NIST rules to reduce long sequences of repeated characters. |
|
| 87 | - $result = 0; |
|
| 88 | - $charmult = array_fill(0, 256, 1); |
|
| 89 | - for ($x = 0; $x < $y; $x++) |
|
| 90 | - { |
|
| 91 | - $tempchr = ord(substr($password, $x, 1)); |
|
| 92 | - if ($x > 19) $result += $charmult[$tempchr]; |
|
| 93 | - else if ($x > 7) $result += $charmult[$tempchr] * 1.5; |
|
| 94 | - else if ($x > 0) $result += $charmult[$tempchr] * 2; |
|
| 95 | - else $result += 4; |
|
| 96 | - |
|
| 97 | - $charmult[$tempchr] *= 0.75; |
|
| 98 | - } |
|
| 99 | - |
|
| 100 | - return $result; |
|
| 101 | - } |
|
| 102 | - else |
|
| 103 | - { |
|
| 104 | - if ($y > 20) return 4 + (7 * 2) + (12 * 1.5) + $y - 20; |
|
| 105 | - if ($y > 8) return 4 + (7 * 2) + (($y - 8) * 1.5); |
|
| 106 | - if ($y > 1) return 4 + (($y - 1) * 2); |
|
| 107 | - |
|
| 108 | - return ($y == 1 ? 4 : 0); |
|
| 109 | - } |
|
| 110 | - } |
|
| 111 | - |
|
| 112 | - //-------------------------------------------------------------------- |
|
| 113 | - |
|
| 114 | - /** |
|
| 115 | - * Determines whether a password is strong enough to use. You should check |
|
| 116 | - * the password against this method and reject it if the password is not |
|
| 117 | - * strong enough. |
|
| 118 | - * |
|
| 119 | - * The following guidelines come from the author's tests against 10.4 million actual passwords |
|
| 120 | - * ( see post: http://cubicspot.blogspot.com/2012/01/how-to-calculate-password-strength-part.html ) |
|
| 121 | - * and represents the suggested minimum entropy bits for different types of sites: |
|
| 122 | - * |
|
| 123 | - * - 18 bits of entropy = minimum for ANY website. |
|
| 124 | - * - 25 bits of entropy = minimum for a general purpose web service used relatively widely (e.g. Hotmail). |
|
| 125 | - * - 30 bits of entropy = minimum for a web service with business critical applications (e.g. SAAS). |
|
| 126 | - * - 40 bits of entropy = minimum for a bank or other financial service. |
|
| 127 | - * |
|
| 128 | - * The algorithm is based upon a modified version of the NIST rules which suggest the following: |
|
| 129 | - * |
|
| 130 | - * - The first byte counts as 4 bits. |
|
| 131 | - * - The next 7 bytes count as 2 bits each. |
|
| 132 | - * - The next 12 bytes count as 1.5 bits each. |
|
| 133 | - * - Anything beyond that counts as 1 bit each. |
|
| 134 | - * - Mixed case + non-alphanumeric = up to 6 extra bits. |
|
| 135 | - * |
|
| 136 | - * @param string $password - The password to check |
|
| 137 | - * @param int $minbits - Minimum "entropy bits" that is allowed |
|
| 138 | - * @param bool $usedict - Should we check the password against a 300,000 word English dictionary? |
|
| 139 | - * @param int $minwordlen - |
|
| 140 | - * @return bool |
|
| 141 | - */ |
|
| 142 | - public static function isStrongPassword($password, $minbits = 18, $usedict = false, $minwordlen = 4) |
|
| 143 | - { |
|
| 144 | - // NIST password strength rules allow up to 6 extra bits for mixed case and non-alphabetic. |
|
| 145 | - $upper = false; |
|
| 146 | - $lower = false; |
|
| 147 | - $numeric = false; |
|
| 148 | - $other = false; |
|
| 149 | - $space = false; |
|
| 150 | - $y = strlen($password); |
|
| 151 | - for ($x = 0; $x < $y; $x++) |
|
| 152 | - { |
|
| 153 | - $tempchr = ord(substr($password, $x, 1)); |
|
| 154 | - if ($tempchr >= ord("A") && $tempchr <= ord("Z")) $upper = true; |
|
| 155 | - else if ($tempchr >= ord("a") && $tempchr <= ord("z")) $lower = true; |
|
| 156 | - else if ($tempchr >= ord("0") && $tempchr <= ord("9")) $numeric = true; |
|
| 157 | - else if ($tempchr == ord(" ")) $space = true; |
|
| 158 | - else $other = true; |
|
| 159 | - } |
|
| 160 | - $extrabits = ($upper && $lower && $other ? ($numeric ? 6 : 5) : ($numeric && !$upper && !$lower ? ($other ? -2 : -6) : 0)); |
|
| 161 | - if (!$space) $extrabits -= 2; |
|
| 162 | - else if (count(explode(" ", preg_replace('/\s+/', " ", $password))) > 3) $extrabits++; |
|
| 163 | - $result = self::getNISTNumBits($password, true) + $extrabits; |
|
| 164 | - |
|
| 165 | - $password = strtolower($password); |
|
| 166 | - $revpassword = strrev($password); |
|
| 167 | - $numbits = self::getNISTNumBits($password) + $extrabits; |
|
| 168 | - if ($result > $numbits) $result = $numbits; |
|
| 169 | - |
|
| 170 | - // Remove QWERTY strings. |
|
| 171 | - $qwertystrs = array( |
|
| 172 | - "1234567890-qwertyuiopasdfghjkl;zxcvbnm,./", |
|
| 173 | - "1qaz2wsx3edc4rfv5tgb6yhn7ujm8ik,9ol.0p;/-['=]:?_{\"+}", |
|
| 174 | - "1qaz2wsx3edc4rfv5tgb6yhn7ujm8ik9ol0p", |
|
| 175 | - "qazwsxedcrfvtgbyhnujmik,ol.p;/-['=]:?_{\"+}", |
|
| 176 | - "qazwsxedcrfvtgbyhnujmikolp", |
|
| 177 | - "]\"/=[;.-pl,0okm9ijn8uhb7ygv6tfc5rdx4esz3wa2q1", |
|
| 178 | - "pl0okm9ijn8uhb7ygv6tfc5rdx4esz3wa2q1", |
|
| 179 | - "]\"/[;.pl,okmijnuhbygvtfcrdxeszwaq", |
|
| 180 | - "plokmijnuhbygvtfcrdxeszwaq", |
|
| 181 | - "014725836914702583697894561230258/369*+-*/", |
|
| 182 | - "abcdefghijklmnopqrstuvwxyz" |
|
| 183 | - ); |
|
| 184 | - foreach ($qwertystrs as $qwertystr) |
|
| 185 | - { |
|
| 186 | - $qpassword = $password; |
|
| 187 | - $qrevpassword = $revpassword; |
|
| 188 | - $z = 6; |
|
| 189 | - do |
|
| 190 | - { |
|
| 191 | - $y = strlen($qwertystr) - $z; |
|
| 192 | - for ($x = 0; $x < $y; $x++) |
|
| 193 | - { |
|
| 194 | - $str = substr($qwertystr, $x, $z); |
|
| 195 | - $qpassword = str_replace($str, "*", $qpassword); |
|
| 196 | - $qrevpassword = str_replace($str, "*", $qrevpassword); |
|
| 197 | - } |
|
| 198 | - |
|
| 199 | - $z--; |
|
| 200 | - } while ($z > 2); |
|
| 201 | - |
|
| 202 | - $numbits = self::getNISTNumBits($qpassword) + $extrabits; |
|
| 203 | - if ($result > $numbits) $result = $numbits; |
|
| 204 | - $numbits = self::getNISTNumBits($qrevpassword) + $extrabits; |
|
| 205 | - if ($result > $numbits) $result = $numbits; |
|
| 206 | - |
|
| 207 | - if ($result < $minbits) return false; |
|
| 208 | - } |
|
| 209 | - |
|
| 210 | - if ($usedict && $result >= $minbits) |
|
| 211 | - { |
|
| 212 | - $passwords = array(); |
|
| 213 | - |
|
| 214 | - // Add keyboard shifting password variants. |
|
| 215 | - $keyboardmap_down_noshift = array( |
|
| 216 | - "z" => "", "x" => "", "c" => "", "v" => "", "b" => "", "n" => "", "m" => "", "," => "", "." => "", "/" => "", "<" => "", ">" => "", "?" => "" |
|
| 217 | - ); |
|
| 218 | - if ($password == str_replace(array_keys($keyboardmap_down_noshift), array_values($keyboardmap_down_noshift), $password)) |
|
| 219 | - { |
|
| 220 | - $keyboardmap_downright = array( |
|
| 221 | - "a" => "z", |
|
| 222 | - "q" => "a", |
|
| 223 | - "1" => "q", |
|
| 224 | - "s" => "x", |
|
| 225 | - "w" => "s", |
|
| 226 | - "2" => "w", |
|
| 227 | - "d" => "c", |
|
| 228 | - "e" => "d", |
|
| 229 | - "3" => "e", |
|
| 230 | - "f" => "v", |
|
| 231 | - "r" => "f", |
|
| 232 | - "4" => "r", |
|
| 233 | - "g" => "b", |
|
| 234 | - "t" => "g", |
|
| 235 | - "5" => "t", |
|
| 236 | - "h" => "n", |
|
| 237 | - "y" => "h", |
|
| 238 | - "6" => "y", |
|
| 239 | - "j" => "m", |
|
| 240 | - "u" => "j", |
|
| 241 | - "7" => "u", |
|
| 242 | - "i" => "k", |
|
| 243 | - "8" => "i", |
|
| 244 | - "o" => "l", |
|
| 245 | - "9" => "o", |
|
| 246 | - "0" => "p", |
|
| 247 | - ); |
|
| 248 | - |
|
| 249 | - $keyboardmap_downleft = array( |
|
| 250 | - "2" => "q", |
|
| 251 | - "w" => "a", |
|
| 252 | - "3" => "w", |
|
| 253 | - "s" => "z", |
|
| 254 | - "e" => "s", |
|
| 255 | - "4" => "e", |
|
| 256 | - "d" => "x", |
|
| 257 | - "r" => "d", |
|
| 258 | - "5" => "r", |
|
| 259 | - "f" => "c", |
|
| 260 | - "t" => "f", |
|
| 261 | - "6" => "t", |
|
| 262 | - "g" => "v", |
|
| 263 | - "y" => "g", |
|
| 264 | - "7" => "y", |
|
| 265 | - "h" => "b", |
|
| 266 | - "u" => "h", |
|
| 267 | - "8" => "u", |
|
| 268 | - "j" => "n", |
|
| 269 | - "i" => "j", |
|
| 270 | - "9" => "i", |
|
| 271 | - "k" => "m", |
|
| 272 | - "o" => "k", |
|
| 273 | - "0" => "o", |
|
| 274 | - "p" => "l", |
|
| 275 | - "-" => "p", |
|
| 276 | - ); |
|
| 277 | - |
|
| 278 | - $password2 = str_replace(array_keys($keyboardmap_downright), array_values($keyboardmap_downright), $password); |
|
| 279 | - $passwords[] = $password2; |
|
| 280 | - $passwords[] = strrev($password2); |
|
| 281 | - |
|
| 282 | - $password2 = str_replace(array_keys($keyboardmap_downleft), array_values($keyboardmap_downleft), $password); |
|
| 283 | - $passwords[] = $password2; |
|
| 284 | - $passwords[] = strrev($password2); |
|
| 285 | - } |
|
| 286 | - |
|
| 287 | - // Deal with LEET-Speak substitutions. |
|
| 288 | - $leetspeakmap = array( |
|
| 289 | - "@" => "a", |
|
| 290 | - "!" => "i", |
|
| 291 | - "$" => "s", |
|
| 292 | - "1" => "i", |
|
| 293 | - "2" => "z", |
|
| 294 | - "3" => "e", |
|
| 295 | - "4" => "a", |
|
| 296 | - "5" => "s", |
|
| 297 | - "6" => "g", |
|
| 298 | - "7" => "t", |
|
| 299 | - "8" => "b", |
|
| 300 | - "9" => "g", |
|
| 301 | - "0" => "o" |
|
| 302 | - ); |
|
| 303 | - |
|
| 304 | - $password2 = str_replace(array_keys($leetspeakmap), array_values($leetspeakmap), $password); |
|
| 305 | - $passwords[] = $password2; |
|
| 306 | - $passwords[] = strrev($password2); |
|
| 307 | - |
|
| 308 | - $leetspeakmap["1"] = "l"; |
|
| 309 | - $password3 = str_replace(array_keys($leetspeakmap), array_values($leetspeakmap), $password); |
|
| 310 | - if ($password3 != $password2) |
|
| 311 | - { |
|
| 312 | - $passwords[] = $password3; |
|
| 313 | - $passwords[] = strrev($password3); |
|
| 314 | - } |
|
| 315 | - |
|
| 316 | - // Process the password, while looking for words in the dictionary. |
|
| 317 | - $a = ord("a"); |
|
| 318 | - $z = ord("z"); |
|
| 319 | - $data = file_get_contents(DICTIONARY_PATH); |
|
| 320 | - foreach ($passwords as $num => $password) |
|
| 321 | - { |
|
| 322 | - $y = strlen($password); |
|
| 323 | - for ($x = 0; $x < $y; $x++) |
|
| 324 | - { |
|
| 325 | - $tempchr = ord(substr($password, $x, 1)); |
|
| 326 | - if ($tempchr >= $a && $tempchr <= $z) |
|
| 327 | - { |
|
| 328 | - for ($x2 = $x + 1; $x2 < $y; $x2++) |
|
| 329 | - { |
|
| 330 | - $tempchr = ord(substr($password, $x2, 1)); |
|
| 331 | - if ($tempchr < $a || $tempchr > $z) break; |
|
| 332 | - } |
|
| 333 | - |
|
| 334 | - $found = false; |
|
| 335 | - while (!$found && $x2 - $x >= $minwordlen) |
|
| 336 | - { |
|
| 337 | - $word = "/\\n" . substr($password, $x, $minwordlen); |
|
| 338 | - for ($x3 = $x + $minwordlen; $x3 < $x2; $x3++) $word .= "(" . $password{$x3}; |
|
| 339 | - for ($x3 = $x + $minwordlen; $x3 < $x2; $x3++) $word .= ")?"; |
|
| 340 | - $word .= "\\n/"; |
|
| 341 | - |
|
| 342 | - preg_match_all($word, $data, $matches); |
|
| 343 | - if (!count($matches[0])) |
|
| 344 | - { |
|
| 345 | - $password{$x} = "*"; |
|
| 346 | - $x++; |
|
| 347 | - $numbits = self::getNISTNumBits(substr($password, 0, $x)) + $extrabits; |
|
| 348 | - if ($numbits >= $minbits) $found = true; |
|
| 349 | - } |
|
| 350 | - else |
|
| 351 | - { |
|
| 352 | - foreach ($matches[0] as $match) |
|
| 353 | - { |
|
| 354 | - $password2 = str_replace(trim($match), "*", $password); |
|
| 355 | - $numbits = self::getNISTNumBits($password2) + $extrabits; |
|
| 356 | - if ($result > $numbits) $result = $numbits; |
|
| 357 | - |
|
| 358 | - if ($result < $minbits) return false; |
|
| 359 | - } |
|
| 360 | - |
|
| 361 | - $found = true; |
|
| 362 | - } |
|
| 363 | - } |
|
| 364 | - |
|
| 365 | - if ($found) break; |
|
| 366 | - |
|
| 367 | - $x = $x2 - 1; |
|
| 368 | - } |
|
| 369 | - } |
|
| 370 | - } |
|
| 371 | - } |
|
| 372 | - |
|
| 373 | - return $result >= $minbits; |
|
| 374 | - } |
|
| 54 | + /** |
|
| 55 | + * A standardized method for hasing a password before storing |
|
| 56 | + * in the database. |
|
| 57 | + * |
|
| 58 | + * @param $password |
|
| 59 | + * @return bool|mixed|string |
|
| 60 | + */ |
|
| 61 | + public static function hashPassword($password) |
|
| 62 | + { |
|
| 63 | + if (! config_item('auth.hash_cost')) |
|
| 64 | + { |
|
| 65 | + get_instance()->load->config('auth'); |
|
| 66 | + } |
|
| 67 | + |
|
| 68 | + return password_hash($password, PASSWORD_DEFAULT, ['cost' => config_item('auth.hash_cost')]); |
|
| 69 | + } |
|
| 70 | + |
|
| 71 | + //-------------------------------------------------------------------- |
|
| 72 | + |
|
| 73 | + /** |
|
| 74 | + * Determines the number of entropy bits a password has based on |
|
| 75 | + * |
|
| 76 | + * |
|
| 77 | + * @param $password |
|
| 78 | + * @param bool $repeatcalc |
|
| 79 | + * @return int |
|
| 80 | + */ |
|
| 81 | + public static function getNISTNumBits($password, $repeatcalc = false) |
|
| 82 | + { |
|
| 83 | + $y = strlen($password); |
|
| 84 | + if ($repeatcalc) |
|
| 85 | + { |
|
| 86 | + // Variant on NIST rules to reduce long sequences of repeated characters. |
|
| 87 | + $result = 0; |
|
| 88 | + $charmult = array_fill(0, 256, 1); |
|
| 89 | + for ($x = 0; $x < $y; $x++) |
|
| 90 | + { |
|
| 91 | + $tempchr = ord(substr($password, $x, 1)); |
|
| 92 | + if ($x > 19) $result += $charmult[$tempchr]; |
|
| 93 | + else if ($x > 7) $result += $charmult[$tempchr] * 1.5; |
|
| 94 | + else if ($x > 0) $result += $charmult[$tempchr] * 2; |
|
| 95 | + else $result += 4; |
|
| 96 | + |
|
| 97 | + $charmult[$tempchr] *= 0.75; |
|
| 98 | + } |
|
| 99 | + |
|
| 100 | + return $result; |
|
| 101 | + } |
|
| 102 | + else |
|
| 103 | + { |
|
| 104 | + if ($y > 20) return 4 + (7 * 2) + (12 * 1.5) + $y - 20; |
|
| 105 | + if ($y > 8) return 4 + (7 * 2) + (($y - 8) * 1.5); |
|
| 106 | + if ($y > 1) return 4 + (($y - 1) * 2); |
|
| 107 | + |
|
| 108 | + return ($y == 1 ? 4 : 0); |
|
| 109 | + } |
|
| 110 | + } |
|
| 111 | + |
|
| 112 | + //-------------------------------------------------------------------- |
|
| 113 | + |
|
| 114 | + /** |
|
| 115 | + * Determines whether a password is strong enough to use. You should check |
|
| 116 | + * the password against this method and reject it if the password is not |
|
| 117 | + * strong enough. |
|
| 118 | + * |
|
| 119 | + * The following guidelines come from the author's tests against 10.4 million actual passwords |
|
| 120 | + * ( see post: http://cubicspot.blogspot.com/2012/01/how-to-calculate-password-strength-part.html ) |
|
| 121 | + * and represents the suggested minimum entropy bits for different types of sites: |
|
| 122 | + * |
|
| 123 | + * - 18 bits of entropy = minimum for ANY website. |
|
| 124 | + * - 25 bits of entropy = minimum for a general purpose web service used relatively widely (e.g. Hotmail). |
|
| 125 | + * - 30 bits of entropy = minimum for a web service with business critical applications (e.g. SAAS). |
|
| 126 | + * - 40 bits of entropy = minimum for a bank or other financial service. |
|
| 127 | + * |
|
| 128 | + * The algorithm is based upon a modified version of the NIST rules which suggest the following: |
|
| 129 | + * |
|
| 130 | + * - The first byte counts as 4 bits. |
|
| 131 | + * - The next 7 bytes count as 2 bits each. |
|
| 132 | + * - The next 12 bytes count as 1.5 bits each. |
|
| 133 | + * - Anything beyond that counts as 1 bit each. |
|
| 134 | + * - Mixed case + non-alphanumeric = up to 6 extra bits. |
|
| 135 | + * |
|
| 136 | + * @param string $password - The password to check |
|
| 137 | + * @param int $minbits - Minimum "entropy bits" that is allowed |
|
| 138 | + * @param bool $usedict - Should we check the password against a 300,000 word English dictionary? |
|
| 139 | + * @param int $minwordlen - |
|
| 140 | + * @return bool |
|
| 141 | + */ |
|
| 142 | + public static function isStrongPassword($password, $minbits = 18, $usedict = false, $minwordlen = 4) |
|
| 143 | + { |
|
| 144 | + // NIST password strength rules allow up to 6 extra bits for mixed case and non-alphabetic. |
|
| 145 | + $upper = false; |
|
| 146 | + $lower = false; |
|
| 147 | + $numeric = false; |
|
| 148 | + $other = false; |
|
| 149 | + $space = false; |
|
| 150 | + $y = strlen($password); |
|
| 151 | + for ($x = 0; $x < $y; $x++) |
|
| 152 | + { |
|
| 153 | + $tempchr = ord(substr($password, $x, 1)); |
|
| 154 | + if ($tempchr >= ord("A") && $tempchr <= ord("Z")) $upper = true; |
|
| 155 | + else if ($tempchr >= ord("a") && $tempchr <= ord("z")) $lower = true; |
|
| 156 | + else if ($tempchr >= ord("0") && $tempchr <= ord("9")) $numeric = true; |
|
| 157 | + else if ($tempchr == ord(" ")) $space = true; |
|
| 158 | + else $other = true; |
|
| 159 | + } |
|
| 160 | + $extrabits = ($upper && $lower && $other ? ($numeric ? 6 : 5) : ($numeric && !$upper && !$lower ? ($other ? -2 : -6) : 0)); |
|
| 161 | + if (!$space) $extrabits -= 2; |
|
| 162 | + else if (count(explode(" ", preg_replace('/\s+/', " ", $password))) > 3) $extrabits++; |
|
| 163 | + $result = self::getNISTNumBits($password, true) + $extrabits; |
|
| 164 | + |
|
| 165 | + $password = strtolower($password); |
|
| 166 | + $revpassword = strrev($password); |
|
| 167 | + $numbits = self::getNISTNumBits($password) + $extrabits; |
|
| 168 | + if ($result > $numbits) $result = $numbits; |
|
| 169 | + |
|
| 170 | + // Remove QWERTY strings. |
|
| 171 | + $qwertystrs = array( |
|
| 172 | + "1234567890-qwertyuiopasdfghjkl;zxcvbnm,./", |
|
| 173 | + "1qaz2wsx3edc4rfv5tgb6yhn7ujm8ik,9ol.0p;/-['=]:?_{\"+}", |
|
| 174 | + "1qaz2wsx3edc4rfv5tgb6yhn7ujm8ik9ol0p", |
|
| 175 | + "qazwsxedcrfvtgbyhnujmik,ol.p;/-['=]:?_{\"+}", |
|
| 176 | + "qazwsxedcrfvtgbyhnujmikolp", |
|
| 177 | + "]\"/=[;.-pl,0okm9ijn8uhb7ygv6tfc5rdx4esz3wa2q1", |
|
| 178 | + "pl0okm9ijn8uhb7ygv6tfc5rdx4esz3wa2q1", |
|
| 179 | + "]\"/[;.pl,okmijnuhbygvtfcrdxeszwaq", |
|
| 180 | + "plokmijnuhbygvtfcrdxeszwaq", |
|
| 181 | + "014725836914702583697894561230258/369*+-*/", |
|
| 182 | + "abcdefghijklmnopqrstuvwxyz" |
|
| 183 | + ); |
|
| 184 | + foreach ($qwertystrs as $qwertystr) |
|
| 185 | + { |
|
| 186 | + $qpassword = $password; |
|
| 187 | + $qrevpassword = $revpassword; |
|
| 188 | + $z = 6; |
|
| 189 | + do |
|
| 190 | + { |
|
| 191 | + $y = strlen($qwertystr) - $z; |
|
| 192 | + for ($x = 0; $x < $y; $x++) |
|
| 193 | + { |
|
| 194 | + $str = substr($qwertystr, $x, $z); |
|
| 195 | + $qpassword = str_replace($str, "*", $qpassword); |
|
| 196 | + $qrevpassword = str_replace($str, "*", $qrevpassword); |
|
| 197 | + } |
|
| 198 | + |
|
| 199 | + $z--; |
|
| 200 | + } while ($z > 2); |
|
| 201 | + |
|
| 202 | + $numbits = self::getNISTNumBits($qpassword) + $extrabits; |
|
| 203 | + if ($result > $numbits) $result = $numbits; |
|
| 204 | + $numbits = self::getNISTNumBits($qrevpassword) + $extrabits; |
|
| 205 | + if ($result > $numbits) $result = $numbits; |
|
| 206 | + |
|
| 207 | + if ($result < $minbits) return false; |
|
| 208 | + } |
|
| 209 | + |
|
| 210 | + if ($usedict && $result >= $minbits) |
|
| 211 | + { |
|
| 212 | + $passwords = array(); |
|
| 213 | + |
|
| 214 | + // Add keyboard shifting password variants. |
|
| 215 | + $keyboardmap_down_noshift = array( |
|
| 216 | + "z" => "", "x" => "", "c" => "", "v" => "", "b" => "", "n" => "", "m" => "", "," => "", "." => "", "/" => "", "<" => "", ">" => "", "?" => "" |
|
| 217 | + ); |
|
| 218 | + if ($password == str_replace(array_keys($keyboardmap_down_noshift), array_values($keyboardmap_down_noshift), $password)) |
|
| 219 | + { |
|
| 220 | + $keyboardmap_downright = array( |
|
| 221 | + "a" => "z", |
|
| 222 | + "q" => "a", |
|
| 223 | + "1" => "q", |
|
| 224 | + "s" => "x", |
|
| 225 | + "w" => "s", |
|
| 226 | + "2" => "w", |
|
| 227 | + "d" => "c", |
|
| 228 | + "e" => "d", |
|
| 229 | + "3" => "e", |
|
| 230 | + "f" => "v", |
|
| 231 | + "r" => "f", |
|
| 232 | + "4" => "r", |
|
| 233 | + "g" => "b", |
|
| 234 | + "t" => "g", |
|
| 235 | + "5" => "t", |
|
| 236 | + "h" => "n", |
|
| 237 | + "y" => "h", |
|
| 238 | + "6" => "y", |
|
| 239 | + "j" => "m", |
|
| 240 | + "u" => "j", |
|
| 241 | + "7" => "u", |
|
| 242 | + "i" => "k", |
|
| 243 | + "8" => "i", |
|
| 244 | + "o" => "l", |
|
| 245 | + "9" => "o", |
|
| 246 | + "0" => "p", |
|
| 247 | + ); |
|
| 248 | + |
|
| 249 | + $keyboardmap_downleft = array( |
|
| 250 | + "2" => "q", |
|
| 251 | + "w" => "a", |
|
| 252 | + "3" => "w", |
|
| 253 | + "s" => "z", |
|
| 254 | + "e" => "s", |
|
| 255 | + "4" => "e", |
|
| 256 | + "d" => "x", |
|
| 257 | + "r" => "d", |
|
| 258 | + "5" => "r", |
|
| 259 | + "f" => "c", |
|
| 260 | + "t" => "f", |
|
| 261 | + "6" => "t", |
|
| 262 | + "g" => "v", |
|
| 263 | + "y" => "g", |
|
| 264 | + "7" => "y", |
|
| 265 | + "h" => "b", |
|
| 266 | + "u" => "h", |
|
| 267 | + "8" => "u", |
|
| 268 | + "j" => "n", |
|
| 269 | + "i" => "j", |
|
| 270 | + "9" => "i", |
|
| 271 | + "k" => "m", |
|
| 272 | + "o" => "k", |
|
| 273 | + "0" => "o", |
|
| 274 | + "p" => "l", |
|
| 275 | + "-" => "p", |
|
| 276 | + ); |
|
| 277 | + |
|
| 278 | + $password2 = str_replace(array_keys($keyboardmap_downright), array_values($keyboardmap_downright), $password); |
|
| 279 | + $passwords[] = $password2; |
|
| 280 | + $passwords[] = strrev($password2); |
|
| 281 | + |
|
| 282 | + $password2 = str_replace(array_keys($keyboardmap_downleft), array_values($keyboardmap_downleft), $password); |
|
| 283 | + $passwords[] = $password2; |
|
| 284 | + $passwords[] = strrev($password2); |
|
| 285 | + } |
|
| 286 | + |
|
| 287 | + // Deal with LEET-Speak substitutions. |
|
| 288 | + $leetspeakmap = array( |
|
| 289 | + "@" => "a", |
|
| 290 | + "!" => "i", |
|
| 291 | + "$" => "s", |
|
| 292 | + "1" => "i", |
|
| 293 | + "2" => "z", |
|
| 294 | + "3" => "e", |
|
| 295 | + "4" => "a", |
|
| 296 | + "5" => "s", |
|
| 297 | + "6" => "g", |
|
| 298 | + "7" => "t", |
|
| 299 | + "8" => "b", |
|
| 300 | + "9" => "g", |
|
| 301 | + "0" => "o" |
|
| 302 | + ); |
|
| 303 | + |
|
| 304 | + $password2 = str_replace(array_keys($leetspeakmap), array_values($leetspeakmap), $password); |
|
| 305 | + $passwords[] = $password2; |
|
| 306 | + $passwords[] = strrev($password2); |
|
| 307 | + |
|
| 308 | + $leetspeakmap["1"] = "l"; |
|
| 309 | + $password3 = str_replace(array_keys($leetspeakmap), array_values($leetspeakmap), $password); |
|
| 310 | + if ($password3 != $password2) |
|
| 311 | + { |
|
| 312 | + $passwords[] = $password3; |
|
| 313 | + $passwords[] = strrev($password3); |
|
| 314 | + } |
|
| 315 | + |
|
| 316 | + // Process the password, while looking for words in the dictionary. |
|
| 317 | + $a = ord("a"); |
|
| 318 | + $z = ord("z"); |
|
| 319 | + $data = file_get_contents(DICTIONARY_PATH); |
|
| 320 | + foreach ($passwords as $num => $password) |
|
| 321 | + { |
|
| 322 | + $y = strlen($password); |
|
| 323 | + for ($x = 0; $x < $y; $x++) |
|
| 324 | + { |
|
| 325 | + $tempchr = ord(substr($password, $x, 1)); |
|
| 326 | + if ($tempchr >= $a && $tempchr <= $z) |
|
| 327 | + { |
|
| 328 | + for ($x2 = $x + 1; $x2 < $y; $x2++) |
|
| 329 | + { |
|
| 330 | + $tempchr = ord(substr($password, $x2, 1)); |
|
| 331 | + if ($tempchr < $a || $tempchr > $z) break; |
|
| 332 | + } |
|
| 333 | + |
|
| 334 | + $found = false; |
|
| 335 | + while (!$found && $x2 - $x >= $minwordlen) |
|
| 336 | + { |
|
| 337 | + $word = "/\\n" . substr($password, $x, $minwordlen); |
|
| 338 | + for ($x3 = $x + $minwordlen; $x3 < $x2; $x3++) $word .= "(" . $password{$x3}; |
|
| 339 | + for ($x3 = $x + $minwordlen; $x3 < $x2; $x3++) $word .= ")?"; |
|
| 340 | + $word .= "\\n/"; |
|
| 341 | + |
|
| 342 | + preg_match_all($word, $data, $matches); |
|
| 343 | + if (!count($matches[0])) |
|
| 344 | + { |
|
| 345 | + $password{$x} = "*"; |
|
| 346 | + $x++; |
|
| 347 | + $numbits = self::getNISTNumBits(substr($password, 0, $x)) + $extrabits; |
|
| 348 | + if ($numbits >= $minbits) $found = true; |
|
| 349 | + } |
|
| 350 | + else |
|
| 351 | + { |
|
| 352 | + foreach ($matches[0] as $match) |
|
| 353 | + { |
|
| 354 | + $password2 = str_replace(trim($match), "*", $password); |
|
| 355 | + $numbits = self::getNISTNumBits($password2) + $extrabits; |
|
| 356 | + if ($result > $numbits) $result = $numbits; |
|
| 357 | + |
|
| 358 | + if ($result < $minbits) return false; |
|
| 359 | + } |
|
| 360 | + |
|
| 361 | + $found = true; |
|
| 362 | + } |
|
| 363 | + } |
|
| 364 | + |
|
| 365 | + if ($found) break; |
|
| 366 | + |
|
| 367 | + $x = $x2 - 1; |
|
| 368 | + } |
|
| 369 | + } |
|
| 370 | + } |
|
| 371 | + } |
|
| 372 | + |
|
| 373 | + return $result >= $minbits; |
|
| 374 | + } |
|
| 375 | 375 | } |
@@ -1,34 +1,34 @@ discard block |
||
| 1 | 1 | <?php |
| 2 | 2 | /** |
| 3 | - * Sprint |
|
| 4 | - * |
|
| 5 | - * A set of power tools to enhance the CodeIgniter framework and provide consistent workflow. |
|
| 6 | - * |
|
| 7 | - * Permission is hereby granted, free of charge, to any person obtaining a copy |
|
| 8 | - * of this software and associated documentation files (the "Software"), to deal |
|
| 9 | - * in the Software without restriction, including without limitation the rights |
|
| 10 | - * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|
| 11 | - * copies of the Software, and to permit persons to whom the Software is |
|
| 12 | - * furnished to do so, subject to the following conditions: |
|
| 13 | - * |
|
| 14 | - * The above copyright notice and this permission notice shall be included in |
|
| 15 | - * all copies or substantial portions of the Software. |
|
| 16 | - * |
|
| 17 | - * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|
| 18 | - * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|
| 19 | - * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|
| 20 | - * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|
| 21 | - * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|
| 22 | - * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN |
|
| 23 | - * THE SOFTWARE. |
|
| 24 | - * |
|
| 25 | - * @package Sprint |
|
| 26 | - * @author Lonnie Ezell |
|
| 27 | - * @copyright Copyright 2014-2015, New Myth Media, LLC (http://newmythmedia.com) |
|
| 28 | - * @license http://opensource.org/licenses/MIT (MIT) |
|
| 29 | - * @link http://sprintphp.com |
|
| 30 | - * @since Version 1.0 |
|
| 31 | - */ |
|
| 3 | + * Sprint |
|
| 4 | + * |
|
| 5 | + * A set of power tools to enhance the CodeIgniter framework and provide consistent workflow. |
|
| 6 | + * |
|
| 7 | + * Permission is hereby granted, free of charge, to any person obtaining a copy |
|
| 8 | + * of this software and associated documentation files (the "Software"), to deal |
|
| 9 | + * in the Software without restriction, including without limitation the rights |
|
| 10 | + * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
|
| 11 | + * copies of the Software, and to permit persons to whom the Software is |
|
| 12 | + * furnished to do so, subject to the following conditions: |
|
| 13 | + * |
|
| 14 | + * The above copyright notice and this permission notice shall be included in |
|
| 15 | + * all copies or substantial portions of the Software. |
|
| 16 | + * |
|
| 17 | + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
|
| 18 | + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
|
| 19 | + * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
|
| 20 | + * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
|
| 21 | + * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
|
| 22 | + * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN |
|
| 23 | + * THE SOFTWARE. |
|
| 24 | + * |
|
| 25 | + * @package Sprint |
|
| 26 | + * @author Lonnie Ezell |
|
| 27 | + * @copyright Copyright 2014-2015, New Myth Media, LLC (http://newmythmedia.com) |
|
| 28 | + * @license http://opensource.org/licenses/MIT (MIT) |
|
| 29 | + * @link http://sprintphp.com |
|
| 30 | + * @since Version 1.0 |
|
| 31 | + */ |
|
| 32 | 32 | |
| 33 | 33 | use \Myth\Route as Route; |
| 34 | 34 | use \Myth\Auth\LocalAuthentication as LocalAuthentication; |
@@ -36,225 +36,225 @@ discard block |
||
| 36 | 36 | class Auth extends \Myth\Controllers\ThemedController |
| 37 | 37 | { |
| 38 | 38 | |
| 39 | - public function __construct() |
|
| 40 | - { |
|
| 41 | - parent::__construct(); |
|
| 42 | - |
|
| 43 | - $this->config->load('auth'); |
|
| 44 | - $this->lang->load('auth'); |
|
| 45 | - $this->load->library('session'); |
|
| 46 | - } |
|
| 47 | - |
|
| 48 | - //-------------------------------------------------------------------- |
|
| 49 | - |
|
| 50 | - public function login() |
|
| 51 | - { |
|
| 52 | - $this->load->helper('form'); |
|
| 53 | - |
|
| 54 | - $auth = new LocalAuthentication(); |
|
| 55 | - $this->load->model('user_model'); |
|
| 56 | - $auth->useModel($this->user_model); |
|
| 57 | - |
|
| 58 | - $redirect_url = $this->session->userdata('redirect_url'); |
|
| 59 | - |
|
| 60 | - // No need to login again if they are already logged in... |
|
| 61 | - if ($auth->isLoggedIn()) |
|
| 62 | - { |
|
| 63 | - unset($_SESSION['redirect_url']); |
|
| 64 | - redirect($redirect_url); |
|
| 65 | - } |
|
| 66 | - |
|
| 67 | - if ($this->input->post()) |
|
| 68 | - { |
|
| 69 | - $post_data = [ |
|
| 70 | - 'email' => $this->input->post('email'), |
|
| 71 | - 'password' => $this->input->post('password') |
|
| 72 | - ]; |
|
| 73 | - |
|
| 74 | - $remember = (bool)$this->input->post('remember'); |
|
| 75 | - |
|
| 76 | - if ($auth->login($post_data, $remember)) |
|
| 77 | - { |
|
| 78 | - // Is the user being forced to reset their password? |
|
| 79 | - if ($auth->user()['force_pass_reset'] == 1) |
|
| 80 | - { |
|
| 81 | - redirect( Route::named('change_pass') ); |
|
| 82 | - } |
|
| 83 | - |
|
| 84 | - unset($_SESSION['redirect_url']); |
|
| 85 | - $this->setMessage(lang('auth.did_login'), 'success'); |
|
| 86 | - redirect($redirect_url); |
|
| 87 | - } |
|
| 88 | - |
|
| 89 | - $this->setMessage($auth->error(), 'danger'); |
|
| 90 | - } |
|
| 91 | - |
|
| 92 | - $this->themer->setLayout('login'); |
|
| 93 | - $this->render(); |
|
| 94 | - } |
|
| 95 | - |
|
| 96 | - //-------------------------------------------------------------------- |
|
| 97 | - |
|
| 98 | - public function logout() |
|
| 99 | - { |
|
| 100 | - $auth = new LocalAuthentication(); |
|
| 101 | - $this->load->model('user_model'); |
|
| 102 | - $auth->useModel($this->user_model); |
|
| 103 | - |
|
| 104 | - if ($auth->isLoggedIn()) |
|
| 105 | - { |
|
| 106 | - $auth->logout(); |
|
| 107 | - |
|
| 108 | - $this->setMessage(lang('auth.did_logout'), 'success'); |
|
| 109 | - } |
|
| 110 | - |
|
| 111 | - redirect('/'); |
|
| 112 | - } |
|
| 113 | - |
|
| 114 | - //-------------------------------------------------------------------- |
|
| 115 | - |
|
| 116 | - public function register() |
|
| 117 | - { |
|
| 118 | - $this->load->helper('form'); |
|
| 119 | - |
|
| 120 | - if ($this->input->post()) |
|
| 121 | - { |
|
| 122 | - $auth = new LocalAuthentication(); |
|
| 123 | - $this->load->model('user_model'); |
|
| 124 | - $auth->useModel($this->user_model); |
|
| 125 | - |
|
| 126 | - $post_data = [ |
|
| 127 | - 'first_name' => $this->input->post('first_name'), |
|
| 128 | - 'last_name' => $this->input->post('last_name'), |
|
| 129 | - 'email' => $this->input->post('email'), |
|
| 130 | - 'username' => $this->input->post('username'), |
|
| 131 | - 'password' => $this->input->post('password'), |
|
| 132 | - 'pass_confirm' => $this->input->post('pass_confirm') |
|
| 133 | - ]; |
|
| 134 | - |
|
| 135 | - if ($auth->registerUser($post_data)) |
|
| 136 | - { |
|
| 137 | - $this->setMessage(lang('auth.did_register'), 'success'); |
|
| 138 | - redirect( Route::named('login') ); |
|
| 139 | - } |
|
| 140 | - else |
|
| 141 | - { |
|
| 142 | - $this->setMessage($auth->error(), 'danger'); |
|
| 143 | - } |
|
| 144 | - } |
|
| 145 | - |
|
| 146 | - $this->addScript('register.js'); |
|
| 147 | - $this->themer->setLayout('login'); |
|
| 148 | - $this->render(); |
|
| 149 | - } |
|
| 150 | - |
|
| 151 | - //-------------------------------------------------------------------- |
|
| 152 | - |
|
| 153 | - public function activate_user() |
|
| 154 | - { |
|
| 155 | - $this->load->helper('form'); |
|
| 156 | - |
|
| 157 | - if ($this->input->post()) |
|
| 158 | - { |
|
| 159 | - $auth = new LocalAuthentication(); |
|
| 160 | - $this->load->model('user_model'); |
|
| 161 | - $auth->useModel($this->user_model); |
|
| 162 | - |
|
| 163 | - $post_data = [ |
|
| 164 | - 'email' => $this->input->post('email'), |
|
| 165 | - 'code' => $this->input->post('code') |
|
| 166 | - ]; |
|
| 167 | - |
|
| 168 | - if ($auth->activateUser($post_data)) |
|
| 169 | - { |
|
| 170 | - $this->setMessage(lang('auth.did_activate'), 'success'); |
|
| 171 | - redirect( Route::named('login') ); |
|
| 172 | - } |
|
| 173 | - else |
|
| 174 | - { |
|
| 175 | - $this->setMessage($auth->error(), 'danger'); |
|
| 176 | - } |
|
| 177 | - } |
|
| 178 | - |
|
| 179 | - $data = [ |
|
| 180 | - 'email' => $this->input->get('e'), |
|
| 181 | - 'code' => $this->input->get('code') |
|
| 182 | - ]; |
|
| 183 | - |
|
| 184 | - $this->themer->setLayout('login'); |
|
| 185 | - $this->render($data); |
|
| 186 | - } |
|
| 187 | - |
|
| 188 | - //-------------------------------------------------------------------- |
|
| 189 | - |
|
| 190 | - |
|
| 191 | - public function forgot_password() |
|
| 192 | - { |
|
| 193 | - $this->load->helper('form'); |
|
| 194 | - |
|
| 195 | - if ($this->input->post()) |
|
| 196 | - { |
|
| 197 | - $auth = new LocalAuthentication(); |
|
| 198 | - $this->load->model('user_model'); |
|
| 199 | - $auth->useModel($this->user_model); |
|
| 200 | - |
|
| 201 | - if ($auth->remindUser($this->input->post('email'))) |
|
| 202 | - { |
|
| 203 | - $this->setMessage(lang('auth.send_success'), 'success'); |
|
| 204 | - redirect( Route::named('reset_pass') ); |
|
| 205 | - } |
|
| 206 | - else |
|
| 207 | - { |
|
| 208 | - $this->setMessage($auth->error(), 'danger'); |
|
| 209 | - } |
|
| 210 | - } |
|
| 211 | - |
|
| 212 | - $this->themer->setLayout('login'); |
|
| 213 | - $this->render(); |
|
| 214 | - } |
|
| 215 | - |
|
| 216 | - //-------------------------------------------------------------------- |
|
| 217 | - |
|
| 218 | - public function reset_password() |
|
| 219 | - { |
|
| 220 | - $this->load->helper('form'); |
|
| 221 | - |
|
| 222 | - if ($this->input->post()) |
|
| 223 | - { |
|
| 224 | - $auth = new LocalAuthentication(); |
|
| 225 | - $this->load->model('user_model'); |
|
| 226 | - $auth->useModel($this->user_model); |
|
| 227 | - |
|
| 228 | - $credentials = [ |
|
| 229 | - 'email' => $this->input->post('email'), |
|
| 230 | - 'code' => $this->input->post('code') |
|
| 231 | - ]; |
|
| 232 | - |
|
| 233 | - $password = $this->input->post('password'); |
|
| 234 | - $pass_confirm = $this->input->post('pass_confirm'); |
|
| 235 | - |
|
| 236 | - if ($auth->resetPassword($credentials, $password, $pass_confirm)) |
|
| 237 | - { |
|
| 238 | - $this->setMessage(lang('auth.new_password_success'), 'success'); |
|
| 239 | - redirect( Route::named('login') ); |
|
| 240 | - } |
|
| 241 | - else |
|
| 242 | - { |
|
| 243 | - $this->setMessage($auth->error(), 'danger'); |
|
| 244 | - } |
|
| 245 | - } |
|
| 246 | - |
|
| 247 | - $data = [ |
|
| 248 | - 'email' => $this->input->get('e'), |
|
| 249 | - 'code' => $this->input->get('code') |
|
| 250 | - ]; |
|
| 251 | - |
|
| 252 | - $this->addScript('register.js'); |
|
| 253 | - $this->themer->setLayout('login'); |
|
| 254 | - $this->render($data); |
|
| 255 | - } |
|
| 256 | - |
|
| 257 | - //-------------------------------------------------------------------- |
|
| 39 | + public function __construct() |
|
| 40 | + { |
|
| 41 | + parent::__construct(); |
|
| 42 | + |
|
| 43 | + $this->config->load('auth'); |
|
| 44 | + $this->lang->load('auth'); |
|
| 45 | + $this->load->library('session'); |
|
| 46 | + } |
|
| 47 | + |
|
| 48 | + //-------------------------------------------------------------------- |
|
| 49 | + |
|
| 50 | + public function login() |
|
| 51 | + { |
|
| 52 | + $this->load->helper('form'); |
|
| 53 | + |
|
| 54 | + $auth = new LocalAuthentication(); |
|
| 55 | + $this->load->model('user_model'); |
|
| 56 | + $auth->useModel($this->user_model); |
|
| 57 | + |
|
| 58 | + $redirect_url = $this->session->userdata('redirect_url'); |
|
| 59 | + |
|
| 60 | + // No need to login again if they are already logged in... |
|
| 61 | + if ($auth->isLoggedIn()) |
|
| 62 | + { |
|
| 63 | + unset($_SESSION['redirect_url']); |
|
| 64 | + redirect($redirect_url); |
|
| 65 | + } |
|
| 66 | + |
|
| 67 | + if ($this->input->post()) |
|
| 68 | + { |
|
| 69 | + $post_data = [ |
|
| 70 | + 'email' => $this->input->post('email'), |
|
| 71 | + 'password' => $this->input->post('password') |
|
| 72 | + ]; |
|
| 73 | + |
|
| 74 | + $remember = (bool)$this->input->post('remember'); |
|
| 75 | + |
|
| 76 | + if ($auth->login($post_data, $remember)) |
|
| 77 | + { |
|
| 78 | + // Is the user being forced to reset their password? |
|
| 79 | + if ($auth->user()['force_pass_reset'] == 1) |
|
| 80 | + { |
|
| 81 | + redirect( Route::named('change_pass') ); |
|
| 82 | + } |
|
| 83 | + |
|
| 84 | + unset($_SESSION['redirect_url']); |
|
| 85 | + $this->setMessage(lang('auth.did_login'), 'success'); |
|
| 86 | + redirect($redirect_url); |
|
| 87 | + } |
|
| 88 | + |
|
| 89 | + $this->setMessage($auth->error(), 'danger'); |
|
| 90 | + } |
|
| 91 | + |
|
| 92 | + $this->themer->setLayout('login'); |
|
| 93 | + $this->render(); |
|
| 94 | + } |
|
| 95 | + |
|
| 96 | + //-------------------------------------------------------------------- |
|
| 97 | + |
|
| 98 | + public function logout() |
|
| 99 | + { |
|
| 100 | + $auth = new LocalAuthentication(); |
|
| 101 | + $this->load->model('user_model'); |
|
| 102 | + $auth->useModel($this->user_model); |
|
| 103 | + |
|
| 104 | + if ($auth->isLoggedIn()) |
|
| 105 | + { |
|
| 106 | + $auth->logout(); |
|
| 107 | + |
|
| 108 | + $this->setMessage(lang('auth.did_logout'), 'success'); |
|
| 109 | + } |
|
| 110 | + |
|
| 111 | + redirect('/'); |
|
| 112 | + } |
|
| 113 | + |
|
| 114 | + //-------------------------------------------------------------------- |
|
| 115 | + |
|
| 116 | + public function register() |
|
| 117 | + { |
|
| 118 | + $this->load->helper('form'); |
|
| 119 | + |
|
| 120 | + if ($this->input->post()) |
|
| 121 | + { |
|
| 122 | + $auth = new LocalAuthentication(); |
|
| 123 | + $this->load->model('user_model'); |
|
| 124 | + $auth->useModel($this->user_model); |
|
| 125 | + |
|
| 126 | + $post_data = [ |
|
| 127 | + 'first_name' => $this->input->post('first_name'), |
|
| 128 | + 'last_name' => $this->input->post('last_name'), |
|
| 129 | + 'email' => $this->input->post('email'), |
|
| 130 | + 'username' => $this->input->post('username'), |
|
| 131 | + 'password' => $this->input->post('password'), |
|
| 132 | + 'pass_confirm' => $this->input->post('pass_confirm') |
|
| 133 | + ]; |
|
| 134 | + |
|
| 135 | + if ($auth->registerUser($post_data)) |
|
| 136 | + { |
|
| 137 | + $this->setMessage(lang('auth.did_register'), 'success'); |
|
| 138 | + redirect( Route::named('login') ); |
|
| 139 | + } |
|
| 140 | + else |
|
| 141 | + { |
|
| 142 | + $this->setMessage($auth->error(), 'danger'); |
|
| 143 | + } |
|
| 144 | + } |
|
| 145 | + |
|
| 146 | + $this->addScript('register.js'); |
|
| 147 | + $this->themer->setLayout('login'); |
|
| 148 | + $this->render(); |
|
| 149 | + } |
|
| 150 | + |
|
| 151 | + //-------------------------------------------------------------------- |
|
| 152 | + |
|
| 153 | + public function activate_user() |
|
| 154 | + { |
|
| 155 | + $this->load->helper('form'); |
|
| 156 | + |
|
| 157 | + if ($this->input->post()) |
|
| 158 | + { |
|
| 159 | + $auth = new LocalAuthentication(); |
|
| 160 | + $this->load->model('user_model'); |
|
| 161 | + $auth->useModel($this->user_model); |
|
| 162 | + |
|
| 163 | + $post_data = [ |
|
| 164 | + 'email' => $this->input->post('email'), |
|
| 165 | + 'code' => $this->input->post('code') |
|
| 166 | + ]; |
|
| 167 | + |
|
| 168 | + if ($auth->activateUser($post_data)) |
|
| 169 | + { |
|
| 170 | + $this->setMessage(lang('auth.did_activate'), 'success'); |
|
| 171 | + redirect( Route::named('login') ); |
|
| 172 | + } |
|
| 173 | + else |
|
| 174 | + { |
|
| 175 | + $this->setMessage($auth->error(), 'danger'); |
|
| 176 | + } |
|
| 177 | + } |
|
| 178 | + |
|
| 179 | + $data = [ |
|
| 180 | + 'email' => $this->input->get('e'), |
|
| 181 | + 'code' => $this->input->get('code') |
|
| 182 | + ]; |
|
| 183 | + |
|
| 184 | + $this->themer->setLayout('login'); |
|
| 185 | + $this->render($data); |
|
| 186 | + } |
|
| 187 | + |
|
| 188 | + //-------------------------------------------------------------------- |
|
| 189 | + |
|
| 190 | + |
|
| 191 | + public function forgot_password() |
|
| 192 | + { |
|
| 193 | + $this->load->helper('form'); |
|
| 194 | + |
|
| 195 | + if ($this->input->post()) |
|
| 196 | + { |
|
| 197 | + $auth = new LocalAuthentication(); |
|
| 198 | + $this->load->model('user_model'); |
|
| 199 | + $auth->useModel($this->user_model); |
|
| 200 | + |
|
| 201 | + if ($auth->remindUser($this->input->post('email'))) |
|
| 202 | + { |
|
| 203 | + $this->setMessage(lang('auth.send_success'), 'success'); |
|
| 204 | + redirect( Route::named('reset_pass') ); |
|
| 205 | + } |
|
| 206 | + else |
|
| 207 | + { |
|
| 208 | + $this->setMessage($auth->error(), 'danger'); |
|
| 209 | + } |
|
| 210 | + } |
|
| 211 | + |
|
| 212 | + $this->themer->setLayout('login'); |
|
| 213 | + $this->render(); |
|
| 214 | + } |
|
| 215 | + |
|
| 216 | + //-------------------------------------------------------------------- |
|
| 217 | + |
|
| 218 | + public function reset_password() |
|
| 219 | + { |
|
| 220 | + $this->load->helper('form'); |
|
| 221 | + |
|
| 222 | + if ($this->input->post()) |
|
| 223 | + { |
|
| 224 | + $auth = new LocalAuthentication(); |
|
| 225 | + $this->load->model('user_model'); |
|
| 226 | + $auth->useModel($this->user_model); |
|
| 227 | + |
|
| 228 | + $credentials = [ |
|
| 229 | + 'email' => $this->input->post('email'), |
|
| 230 | + 'code' => $this->input->post('code') |
|
| 231 | + ]; |
|
| 232 | + |
|
| 233 | + $password = $this->input->post('password'); |
|
| 234 | + $pass_confirm = $this->input->post('pass_confirm'); |
|
| 235 | + |
|
| 236 | + if ($auth->resetPassword($credentials, $password, $pass_confirm)) |
|
| 237 | + { |
|
| 238 | + $this->setMessage(lang('auth.new_password_success'), 'success'); |
|
| 239 | + redirect( Route::named('login') ); |
|
| 240 | + } |
|
| 241 | + else |
|
| 242 | + { |
|
| 243 | + $this->setMessage($auth->error(), 'danger'); |
|
| 244 | + } |
|
| 245 | + } |
|
| 246 | + |
|
| 247 | + $data = [ |
|
| 248 | + 'email' => $this->input->get('e'), |
|
| 249 | + 'code' => $this->input->get('code') |
|
| 250 | + ]; |
|
| 251 | + |
|
| 252 | + $this->addScript('register.js'); |
|
| 253 | + $this->themer->setLayout('login'); |
|
| 254 | + $this->render($data); |
|
| 255 | + } |
|
| 256 | + |
|
| 257 | + //-------------------------------------------------------------------- |
|
| 258 | 258 | |
| 259 | 259 | /** |
| 260 | 260 | * Allows a logged in user to enter their current password |
@@ -320,24 +320,24 @@ discard block |
||
| 320 | 320 | //-------------------------------------------------------------------- |
| 321 | 321 | |
| 322 | 322 | |
| 323 | - //-------------------------------------------------------------------- |
|
| 324 | - // AJAX Methods |
|
| 325 | - //-------------------------------------------------------------------- |
|
| 323 | + //-------------------------------------------------------------------- |
|
| 324 | + // AJAX Methods |
|
| 325 | + //-------------------------------------------------------------------- |
|
| 326 | 326 | |
| 327 | - /** |
|
| 328 | - * Checks the password strength and returns pass/fail. |
|
| 329 | - * |
|
| 330 | - * @param $str |
|
| 331 | - */ |
|
| 332 | - public function password_check($str) |
|
| 333 | - { |
|
| 334 | - $this->load->helper('auth/password'); |
|
| 327 | + /** |
|
| 328 | + * Checks the password strength and returns pass/fail. |
|
| 329 | + * |
|
| 330 | + * @param $str |
|
| 331 | + */ |
|
| 332 | + public function password_check($str) |
|
| 333 | + { |
|
| 334 | + $this->load->helper('auth/password'); |
|
| 335 | 335 | |
| 336 | - $strength = isStrongPassword($str); |
|
| 336 | + $strength = isStrongPassword($str); |
|
| 337 | 337 | |
| 338 | - $this->renderJSON(['status' => $strength ? 'pass' : 'fail']); |
|
| 339 | - } |
|
| 338 | + $this->renderJSON(['status' => $strength ? 'pass' : 'fail']); |
|
| 339 | + } |
|
| 340 | 340 | |
| 341 | - //-------------------------------------------------------------------- |
|
| 341 | + //-------------------------------------------------------------------- |
|
| 342 | 342 | |
| 343 | 343 | } |
@@ -46,7 +46,7 @@ |
||
| 46 | 46 | public function index($target_time = 50) |
| 47 | 47 | { |
| 48 | 48 | // Convert the milliseconds to seconds. |
| 49 | - $target_time = $target_time / 1000; |
|
| 49 | + $target_time = $target_time / 1000; |
|
| 50 | 50 | |
| 51 | 51 | CLI::write('Testing for password hash value with a target time of '. $target_time .' seconds...'); |
| 52 | 52 | |
@@ -32,28 +32,28 @@ |
||
| 32 | 32 | |
| 33 | 33 | if (! function_exists('isStrongPassword')) |
| 34 | 34 | { |
| 35 | - /** |
|
| 36 | - * Works with Myth\Auth\Password to enforce a strong password. |
|
| 37 | - * Uses settings from the auth config file. |
|
| 38 | - * |
|
| 39 | - * @param $password |
|
| 40 | - */ |
|
| 41 | - function isStrongPassword($password) |
|
| 42 | - { |
|
| 43 | - $min_strength = config_item('auth.min_password_strength'); |
|
| 44 | - $use_dict = config_item('auth.use_dictionary'); |
|
| 35 | + /** |
|
| 36 | + * Works with Myth\Auth\Password to enforce a strong password. |
|
| 37 | + * Uses settings from the auth config file. |
|
| 38 | + * |
|
| 39 | + * @param $password |
|
| 40 | + */ |
|
| 41 | + function isStrongPassword($password) |
|
| 42 | + { |
|
| 43 | + $min_strength = config_item('auth.min_password_strength'); |
|
| 44 | + $use_dict = config_item('auth.use_dictionary'); |
|
| 45 | 45 | |
| 46 | - $strong = \Myth\Auth\Password::isStrongPassword($password, $min_strength, $use_dict); |
|
| 46 | + $strong = \Myth\Auth\Password::isStrongPassword($password, $min_strength, $use_dict); |
|
| 47 | 47 | |
| 48 | - if (! $strong) |
|
| 49 | - { |
|
| 50 | - if (isset(get_instance()->form_validation)) |
|
| 51 | - { |
|
| 52 | - get_instance()->form_validation->set_message('isStrongPassword', lang('auth.pass_not_strong')); |
|
| 53 | - } |
|
| 54 | - return false; |
|
| 55 | - } |
|
| 48 | + if (! $strong) |
|
| 49 | + { |
|
| 50 | + if (isset(get_instance()->form_validation)) |
|
| 51 | + { |
|
| 52 | + get_instance()->form_validation->set_message('isStrongPassword', lang('auth.pass_not_strong')); |
|
| 53 | + } |
|
| 54 | + return false; |
|
| 55 | + } |
|
| 56 | 56 | |
| 57 | - return true; |
|
| 58 | - } |
|
| 57 | + return true; |
|
| 58 | + } |
|
| 59 | 59 | } |