1
|
|
|
<?php |
2
|
|
|
|
3
|
|
|
/** |
4
|
|
|
* Sasl library. |
5
|
|
|
* |
6
|
|
|
* Copyright (c) 2002-2003 Richard Heyes, |
7
|
|
|
* 2014-2024 Fabian Grutschus |
8
|
|
|
* All rights reserved. |
9
|
|
|
* |
10
|
|
|
* Redistribution and use in source and binary forms, with or without |
11
|
|
|
* modification, are permitted provided that the following conditions |
12
|
|
|
* are met: |
13
|
|
|
* |
14
|
|
|
* o Redistributions of source code must retain the above copyright |
15
|
|
|
* notice, this list of conditions and the following disclaimer. |
16
|
|
|
* o Redistributions in binary form must reproduce the above copyright |
17
|
|
|
* notice, this list of conditions and the following disclaimer in the |
18
|
|
|
* documentation and/or other materials provided with the distribution.| |
19
|
|
|
* o The names of the authors may not be used to endorse or promote |
20
|
|
|
* products derived from this software without specific prior written |
21
|
|
|
* permission. |
22
|
|
|
* |
23
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
24
|
|
|
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
25
|
|
|
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
26
|
|
|
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
27
|
|
|
* OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
28
|
|
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
29
|
|
|
* LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
30
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
31
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
32
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
33
|
|
|
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
34
|
|
|
* |
35
|
|
|
* @author Richard Heyes <[email protected]> |
36
|
|
|
*/ |
37
|
|
|
|
38
|
|
|
namespace Fabiang\Sasl\Authentication; |
39
|
|
|
|
40
|
|
|
use Fabiang\Sasl\Authentication\AbstractAuthentication; |
41
|
|
|
|
42
|
|
|
/** |
43
|
|
|
* Implmentation of CRAM-MD5 SASL mechanism |
44
|
|
|
* |
45
|
|
|
* @author Richard Heyes <[email protected]> |
46
|
|
|
*/ |
47
|
|
|
class CramMD5 extends AbstractAuthentication implements ChallengeAuthenticationInterface |
48
|
|
|
{ |
49
|
|
|
/** |
50
|
|
|
* Implements the CRAM-MD5 SASL mechanism |
51
|
|
|
* This DOES NOT base64 encode the return value, |
52
|
|
|
* you will need to do that yourself. |
53
|
|
|
* |
54
|
|
|
* @param string $challenge The challenge supplied by the server. |
55
|
|
|
* this should be already base64_decoded. |
56
|
|
|
* |
57
|
|
|
* @return string The string to pass back to the server, of the form |
58
|
|
|
* "<user> <digest>". This is NOT base64_encoded. |
59
|
|
|
*/ |
60
|
2 |
|
public function createResponse($challenge = null) |
61
|
|
|
{ |
62
|
2 |
|
return $this->options->getAuthcid() . ' ' . hash_hmac('md5', $challenge, $this->options->getSecret()); |
|
|
|
|
63
|
|
|
} |
64
|
|
|
} |
65
|
|
|
|