This project is archived and is in readonly mode.
Patch #3 for HTTP Digest Auth
-
Don Parish
Cleaned up git commits so changes easier to follow. Patch has 3 commits: fix for earlier commit, support for using digested password, and support for session-less connections.
-
Gregg Kellogg
I think it's important to get these patches in, but there should be a follow up to deal with the potential unavailability of the session_id. This could be done either by promoting nonce, validate_nonce and opaque to ControllerMethods so that they can be overridden, or to create some other method, such as "nonce_seed" that can be implemented by an application to provide a more secure seed than a potentially unavailable session_id. The advantage of promoting nonce is that a truly persistent nonce value could be saved in the database to allow for the intended semantics of Digest Authentication. The OAuth plugin does this, for example. It can default to the existing method.
-
Repository
- State changed from new to resolved
(from [be7b64b35aac1c9e9063d1d8317f8b1be2a3411c]) Support MD5 passwords for Digest auth and use session_options[:secret] in nonce [#2209 Patch #3 for HTTP Digest Auth state:resolved]
Signed-off-by: Pratik Naik pratiknaik@gmail.com http://github.com/rails/rails/co...
