Hallo alle zusammen.
Ich musste gerade mit entsetzen feststellen, dass der IE8 wohl ein Problem mit dem JavaScript hat, welches ein PWD in MD5 verschlüsselt.
Folgendes Script benutze ich:
<?php
class user_md5fepw {
function md5Challenge($content, $conf) {
$js = '
function superchallenge_pass(form) {
var pass = form.pass.value;
if (pass) {
//alert(pass);
form.pass.value = MD5(form.user.value + ":" + MD5(pass) + ":" + form.challenge.value);
//alert(form.pass.value);
return true;
} else { return false; }
}';
$GLOBALS['TSFE']->JSCode .= $js;
$GLOBALS['TSFE']->additionalHeaderData['tx_kbmd5fepw_newloginbox'] = '<script language="JavaScript" type="text/javascript" src="typo3/md5.js"></script>';
$chal_val = md5(time().getmypid());
$res = $GLOBALS['TYPO3_DB']->exec_INSERTquery('tx_kbmd5fepw_challenge', array('challenge' => $chal_val, 'tstamp' => time()));
return '<input type="hidden" name="challenge" value="'.$chal_val.'" />';
}
}
?>
Im IE 6, IE7, FF2, FF3, Opera, Safari usw funktioniert das problemlos. Jedoch beim IE8 nicht.
Hat da jemand eine Idee?
Cross Posting: http://www.typo3forum.net/forum/typo3-3-x-fragen-probleme/38039-superchallenge_pass-ie8.html#post127931
Hallo digitalfreak,
hast Du schon eine Lösung? ich habe hier gerade dasselbe Problem und kann die Ursache nicht finden...
Bisher nicht. Ich habe es mal als Bug in den Bugtracker aufgenommen.
http://bugs.typo3.org/view.php?id=11491
Hallo,
danke für den Hinweis mit dem Bug, aber ich kapiere nicht was ich da austauchen soll? ich habe die NewLoginBox nicht, ich habe nur felogin den nachfolger, wenn ich aber die Funktionen die im Bug angegeben wurden öffne, sind es die gleichen wie in kb_md5fepw Datei class.tx_kbmd5fepw_newloginbox.php
Also ich verstehe einfach nicht was ich da austauschen soll?
die md5.js ist die Umlaut sicher? Die originale ist es nämlich nicht!
Gruß
Björn
Hi,
http://bugs.typo3.org/view.php?id=11491 hier sagt Torsten schon das das JS nicht passt. Die md5-Verschlüsselung läuft falsch.
Versucht mal folgendes:
class.tx_kbmd5fepw_newloginbox.php
require_once(t3lib_extMgm::extPath('kb_md5fepw').'class.tx_kbmd5fepw_funcs.php');
require_once(PATH_tslib.'class.tslib_pibase.php');
class tx_kbmd5fepw_newloginbox extends tslib_pibase {
function forgotPassword(&$params, &$ref) {
$this->conf = $ref->conf;
$this->pi_setPiVarDefaults();
$this->scriptRelPath = 'pi1/class.tx_kbmd5fepw_newloginbox.php';
$this->extKey = 'kb_md5fepw';
$this->pi_loadLL(1); // Loading the LOCAL_LANG values
$d=$GLOBALS['TSFE']->getStorageSiterootPids();
$res = $GLOBALS['TYPO3_DB']->exec_SELECTquery('uid, username, password', 'fe_users', 'email='.$GLOBALS['TYPO3_DB']->fullQuoteStr(trim($ref->piVars['DATA']['forgot_email']), 'fe_users').' AND pid='.intval($d['_STORAGE_PID']).' '.$GLOBALS['TSFE']->cObj->enableFields('fe_users'));
if ($row = $GLOBALS['TYPO3_DB']->sql_fetch_assoc($res)) {
$new_password = tx_kbmd5fepw_funcs::generatePassword(intval($GLOBALS['TSFE']->config['plugin.']['tx_newloginbox_pi1.']['defaultPasswordLength'])?intval($GLOBALS['TSFE']->config['plugin.']['tx_newloginbox_pi1.']['defaultPasswordLength']):5);
$GLOBALS['TYPO3_DB']->exec_UPDATEquery('fe_users', 'uid='.$row['uid'], array('password' => md5($new_password)));
$msg=sprintf($this->pi_getLL('forgot_password_pswmsg','',1),trim($this->piVars['DATA']['forgot_email']),$row['username'],$new_password);
} else {
$msg=sprintf($this->pi_getLL('forgot_password_no_pswmsg','',1),trim($this->piVars['DATA']['forgot_email']));
}
$params['msg'] = $msg;
return true;
}
function loginFormOnSubmit(&$params, &$ref) {
$js = '
function superchallenge_pass(form) {
var pass = form.pass.value;
if (pass) {
var enc_pass = MD5(pass);
var str = form.user.value+":"+enc_pass+":"+form.challenge.value;
form.pass.value = MD5(str);
return true;
} else {
return false;
}
}
';
$GLOBALS['TSFE']->JSCode .= $js;
$GLOBALS['TSFE']->additionalHeaderData['tx_kbmd5fepw_newloginbox'] = '<script language="JavaScript" type="text/javascript" src="fileadmin/js/md5.js" charset="UTF-8"></script>';
$chal_val = md5(time().getmypid());
$res = $GLOBALS['TYPO3_DB']->exec_INSERTquery('tx_kbmd5fepw_challenge', array('challenge' => $chal_val, 'tstamp' => time()));
$onSubmit = 'superchallenge_pass(this)';
$hidden = '<input type="hidden" name="challenge" value="'.$chal_val.'">';
return array($onSubmit, $hidden);
}
}
Den Pfad zum neuem md5.js natürlich anpassen. Das bekommt ihr hier.
http://www.webtoolkit.info/javascript-md5.html
Und benutzt den felogin, nicht mehr die newloginbox, wird nicht mehr weiterentwickelt.
Hoffe es hilft. (bei mir funktioniert es)