[PEAR-BUG] Bug #18692 [Opn->Csd]: expired token does not throw exception

[email protected]
Newsgroups php.pear.bugs
Message-ID <[email protected]>
Edit report at http://pear.php.net/bugs/bug.php?id=18692&edit=1

 ID:               18692
 Updated by:       [email protected]
 Reported By:      drew at n3x dot ca
 Summary:          expired token does not throw exception
-Status:           Open
+Status:           Closed
 Type:             Bug
 Package:          Services_Atlassian_Crowd
 Operating System: CentOS
 Package Version:  0.9.5
 PHP Version:      5.3.6
-Assigned To:      
+Assigned To:      drewkopp
 Roadmap Versions: 
 New Comment:

-Status:      Open
+Status:      Closed
-Assigned To:
+Assigned To: drewkopp
this turned out to be an issue with my crowd server.


Previous Comments:
------------------------------------------------------------------------

[2011-07-27 21:19:22] drewkopp

Description:
------------
I have been developing a Yii framework extension using this package,
however during development i discovered two small problems.

The isValidPrincipalToken and authenticatePrincipal do not throw
exceptions for expired tokens and invalid usernames respectively.

it seems that the isValidPrinipalToken will throw an exception if the
token is missing and authenticatePrincipal will throw one if the
password is wrong for a real user.

This is unexpected behavior (and somewhat dangerous as it exposes valid
user accounts).

I am not sure if this is related to the package code, or Crowd is simply
not returning appropriate data. 

I would welcome your feedback / comments.

------------------------------------------------------------------------


-- 
Edit this bug report at http://pear.php.net/bugs/bug.php?id=18692&edit=1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.