| line | stmt | bran | cond | sub | pod | time | code | 
| 1 |  |  |  |  |  |  | package Authen::Htpasswd::Util; | 
| 2 | 3 |  |  | 3 |  | 15 | use strict; | 
|  | 3 |  |  |  |  | 5 |  | 
|  | 3 |  |  |  |  | 92 |  | 
| 3 | 3 |  |  | 3 |  | 66137 | use Digest; | 
|  | 3 |  |  |  |  | 2301 |  | 
|  | 3 |  |  |  |  | 73 |  | 
| 4 | 3 |  |  | 3 |  | 18 | use Carp; | 
|  | 3 |  |  |  |  | 6 |  | 
|  | 3 |  |  |  |  | 185 |  | 
| 5 |  |  |  |  |  |  |  | 
| 6 | 3 |  |  | 3 |  | 15 | use vars qw{@ISA @EXPORT}; | 
|  | 3 |  |  |  |  | 5 |  | 
|  | 3 |  |  |  |  | 185 |  | 
| 7 |  |  |  |  |  |  | BEGIN { | 
| 8 | 3 |  |  | 3 |  | 14 | require Exporter; | 
| 9 | 3 |  |  |  |  | 46 | @ISA = qw/ Exporter /; | 
| 10 | 3 |  |  |  |  | 1258 | @EXPORT = qw/ htpasswd_encrypt /; | 
| 11 |  |  |  |  |  |  | } | 
| 12 |  |  |  |  |  |  |  | 
| 13 |  |  |  |  |  |  | my @CRYPT_CHARS = split(//, './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'); | 
| 14 |  |  |  |  |  |  |  | 
| 15 |  |  |  |  |  |  | =head1 NAME | 
| 16 |  |  |  |  |  |  |  | 
| 17 |  |  |  |  |  |  | Authen::Htpasswd::Util - performs encryption of supported .htpasswd formats | 
| 18 |  |  |  |  |  |  |  | 
| 19 |  |  |  |  |  |  | =head1 METHODS | 
| 20 |  |  |  |  |  |  |  | 
| 21 |  |  |  |  |  |  | =head2 htpasswd_encrypt | 
| 22 |  |  |  |  |  |  |  | 
| 23 |  |  |  |  |  |  | htpasswd_encrypt($hash,$password,$hashed_password); | 
| 24 |  |  |  |  |  |  |  | 
| 25 |  |  |  |  |  |  | Encrypts a cleartext $password given the specified $hash (valid values are C, C, C, or C). | 
| 26 |  |  |  |  |  |  | For C and C it is sometimes necessary to pass the old encrypted password as $hashed_password | 
| 27 |  |  |  |  |  |  | to be sure that the new one uses the correct salt. Exported by default. | 
| 28 |  |  |  |  |  |  |  | 
| 29 |  |  |  |  |  |  | =cut | 
| 30 |  |  |  |  |  |  |  | 
| 31 |  |  |  |  |  |  | sub htpasswd_encrypt { | 
| 32 | 53 |  |  | 53 | 1 | 95 | my ($hash,$password,$hashed_password) = @_; | 
| 33 | 53 |  |  |  |  | 352 | my $meth = __PACKAGE__->can("_hash_$hash"); | 
| 34 | 53 | 50 |  |  |  | 130 | croak "don't know how to handle $hash hash" unless $meth; | 
| 35 | 53 |  |  |  |  | 127 | return &$meth($password,$hashed_password); | 
| 36 |  |  |  |  |  |  | } | 
| 37 |  |  |  |  |  |  |  | 
| 38 |  |  |  |  |  |  | =head2 supported_hashes | 
| 39 |  |  |  |  |  |  |  | 
| 40 |  |  |  |  |  |  | my @hashes = Authen::Htpasswd::Util::supported_hashes(); | 
| 41 |  |  |  |  |  |  |  | 
| 42 |  |  |  |  |  |  | Returns an array of hash types available. C and C are always available. C is checked by | 
| 43 |  |  |  |  |  |  | attempting to load it via L. C requires L. | 
| 44 |  |  |  |  |  |  |  | 
| 45 |  |  |  |  |  |  | =cut | 
| 46 |  |  |  |  |  |  |  | 
| 47 |  |  |  |  |  |  | sub supported_hashes { | 
| 48 | 2 |  |  | 2 | 1 | 8 | my @supported = qw/ crypt plain /; | 
| 49 | 2 |  |  |  |  | 6 | eval { Digest->new("SHA-1") }; | 
|  | 2 |  |  |  |  | 19 |  | 
| 50 | 2 | 50 |  |  |  | 12144 | unshift @supported, 'sha1' unless $@; | 
| 51 | 2 |  |  |  |  | 6 | eval { require Crypt::PasswdMD5 }; | 
|  | 2 |  |  |  |  | 7721 |  | 
| 52 | 2 | 50 |  |  |  | 2505 | unshift @supported, 'md5' unless $@; | 
| 53 | 2 |  |  |  |  | 27 | return @supported; | 
| 54 |  |  |  |  |  |  | } | 
| 55 |  |  |  |  |  |  |  | 
| 56 |  |  |  |  |  |  | sub _hash_plain { | 
| 57 | 6 |  |  | 6 |  | 10 | my ($password) = @_; | 
| 58 | 6 |  |  |  |  | 94 | return $password; | 
| 59 |  |  |  |  |  |  | } | 
| 60 |  |  |  |  |  |  |  | 
| 61 |  |  |  |  |  |  | sub _hash_crypt { | 
| 62 | 18 |  |  | 18 |  | 31 | my ($password,$salt) = @_; | 
| 63 | 18 | 100 |  |  |  | 101 | $salt = join('', @CRYPT_CHARS[int rand 64, int rand 64]) unless $salt; | 
| 64 | 18 |  |  |  |  | 2410 | return crypt($password,$salt); | 
| 65 |  |  |  |  |  |  | } | 
| 66 |  |  |  |  |  |  |  | 
| 67 |  |  |  |  |  |  | sub _hash_md5 { | 
| 68 | 15 |  |  | 15 |  | 19 | my ($password,$salt) = @_; | 
| 69 | 15 |  |  |  |  | 119 | require Crypt::PasswdMD5; | 
| 70 | 15 |  |  |  |  | 53 | return Crypt::PasswdMD5::apache_md5_crypt($password,$salt); | 
| 71 |  |  |  |  |  |  | } | 
| 72 |  |  |  |  |  |  |  | 
| 73 |  |  |  |  |  |  | sub _hash_sha1 { | 
| 74 | 14 |  |  | 14 |  | 26 | my ($password) = @_; | 
| 75 | 14 |  |  |  |  | 106 | my $sha1 = Digest->new("SHA-1"); | 
| 76 | 14 |  |  |  |  | 620 | $sha1->add($password); | 
| 77 | 14 |  |  |  |  | 209 | return '{SHA}' . $sha1->b64digest . '='; | 
| 78 |  |  |  |  |  |  | } | 
| 79 |  |  |  |  |  |  |  | 
| 80 |  |  |  |  |  |  | =head1 AUTHOR | 
| 81 |  |  |  |  |  |  |  | 
| 82 |  |  |  |  |  |  | David Kamholz C | 
| 83 |  |  |  |  |  |  |  | 
| 84 |  |  |  |  |  |  | Yuval Kogman | 
| 85 |  |  |  |  |  |  |  | 
| 86 |  |  |  |  |  |  | =head1 COPYRIGHT & LICENSE | 
| 87 |  |  |  |  |  |  |  | 
| 88 |  |  |  |  |  |  | Copyright (c) 2005 - 2007 the aforementioned authors. | 
| 89 |  |  |  |  |  |  |  | 
| 90 |  |  |  |  |  |  | This program is free software; you can redistribute | 
| 91 |  |  |  |  |  |  | it and/or modify it under the same terms as Perl itself. | 
| 92 |  |  |  |  |  |  |  | 
| 93 |  |  |  |  |  |  | =cut | 
| 94 |  |  |  |  |  |  |  | 
| 95 |  |  |  |  |  |  | 1; |