MWSaltedPassword.php 1.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051
  1. <?php
  2. /**
  3. * Implements the MWSaltedPassword class for the MediaWiki software.
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation; either version 2 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License along
  16. * with this program; if not, write to the Free Software Foundation, Inc.,
  17. * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  18. * http://www.gnu.org/copyleft/gpl.html
  19. *
  20. * @file
  21. */
  22. /**
  23. * The old style of MediaWiki password hashing, with a salt. It involves
  24. * running MD5 on the password, and then running MD5 on the salt concatenated
  25. * with the first hash.
  26. *
  27. * @since 1.24
  28. */
  29. class MWSaltedPassword extends ParameterizedPassword {
  30. protected function getDefaultParams() {
  31. return [];
  32. }
  33. protected function getDelimiter() {
  34. return ':';
  35. }
  36. public function crypt( $plaintext ) {
  37. if ( count( $this->args ) == 0 ) {
  38. $this->args[] = MWCryptRand::generateHex( 8 );
  39. }
  40. $this->hash = md5( $this->args[0] . '-' . md5( $plaintext ) );
  41. if ( !is_string( $this->hash ) || strlen( $this->hash ) < 32 ) {
  42. throw new PasswordError( 'Error when hashing password.' );
  43. }
  44. }
  45. }