From 968e9d7a88eeb91e635b88b7e5ae5b795e0b4225 Mon Sep 17 00:00:00 2001 From: "terry%netscape.com" <> Date: Thu, 3 Sep 1998 01:52:48 +0000 Subject: Changed the way password validation works. We now keep a crypt'd version of the password in the database, and check against that. (This is silly, because we're also keeping the plaintext version there, but I have plans...) Stop passing the plaintext password around as a cookie; instead, we have a cookie that references a record in a new database table, logincookies. IMPORTANT: if updating from an older version of Bugzilla, you must run the following commands to keep things working: ./makelogincookiestable.sh echo "alter table profiles add column cryptpassword varchar(64);" | mysql bugs echo "update profiles set cryptpassword = encrypt(password,substring(rand(),3, 4));" | mysql bugs --- makeprofilestable.sh | 1 + 1 file changed, 1 insertion(+) (limited to 'makeprofilestable.sh') diff --git a/makeprofilestable.sh b/makeprofilestable.sh index 2780d6134..76ce65c31 100755 --- a/makeprofilestable.sh +++ b/makeprofilestable.sh @@ -31,6 +31,7 @@ create table profiles ( userid mediumint not null auto_increment primary key, login_name varchar(255) not null, password varchar(16), +cryptpassword varchar(64), realname varchar(255), index(login_name) ); -- cgit v1.2.3-24-g4f1b