Edit report at http://pear.php.net/bugs/bug.php?id=18692&edit=1
ID: 18692
Updated by: [email protected]
Reported By: drew at n3x dot ca
Summary: expired token does not throw exception
-Status: Open
+Status: Closed
Type: Bug
Package: Services_Atlassian_Crowd
Operating System: CentOS
Package Version: 0.9.5
PHP Version: 5.3.6
-Assigned To:
+Assigned To: drewkopp
Roadmap Versions:
New Comment:
-Status: Open
+Status: Closed
-Assigned To:
+Assigned To: drewkopp
this turned out to be an issue with my crowd server.
Previous Comments:
------------------------------------------------------------------------
[2011-07-27 21:19:22] drewkopp
Description:
------------
I have been developing a Yii framework extension using this package,
however during development i discovered two small problems.
The isValidPrincipalToken and authenticatePrincipal do not throw
exceptions for expired tokens and invalid usernames respectively.
it seems that the isValidPrinipalToken will throw an exception if the
token is missing and authenticatePrincipal will throw one if the
password is wrong for a real user.
This is unexpected behavior (and somewhat dangerous as it exposes valid
user accounts).
I am not sure if this is related to the package code, or Crowd is simply
not returning appropriate data.
I would welcome your feedback / comments.
------------------------------------------------------------------------
--
Edit this bug report at http://pear.php.net/bugs/bug.php?id=18692&edit=1
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.