Re: hno's auth_escape patch

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Fri, 15 Feb 2002 01:00:18 +0100

On Thursday 14 February 2002 13.34, Robert Collins wrote:

> We have RFC19 whatever escaping code in libmisc already - no new
> code is needed for helpers, just a new library and one function
> call.

So how do you do this in a shell based authenticator for example?

Reading the : separated format in shell is trivial (IFS), as is it in
all other languages used for the auth helpers.

> > The redirector interface is different. For one thing it is not
> > dependent on the auth scheme.
>
> True. The issues with spaces are constant though - which is why I'm
> suggesting using the url escaped string here.

And I agree that URL escaping is a good way at least where the login
is presented for informal purposes (access.log, redirector).

For the Basic auth interface I pretty much prefer simplicity in the
implementation of the helper.

Regards
Henrik
Received on Thu Feb 14 2002 - 17:00:12 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:14:47 MST