首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >从joomla验证登录凭据!核心结构

从joomla验证登录凭据!核心结构
EN

Stack Overflow用户
提问于 2017-06-21 17:22:31
回答 0查看 162关注 0票数 0

我正在为joomla开发一个插件!但是考虑到脚本的复杂性,我在核心结构之外设计了它。

现在我遇到的唯一问题是,只有在用户有权限的情况下,才允许用户以管理员身份登录一次,并遵循我的插件文件夹。

我的插件在:( pathdotcom/test)文件夹中,所有内容都可以正常工作,但可以向公众开放。

到目前为止,我已经在(test/index.php)中尝试了以下代码:

代码语言:javascript
复制
// Load Joomla! configuration file
require_once('../configuration.php');
// Create a JConfig object
$config = new JConfig();
//import variables
$dbhostname     = $config->host;
$dbusername     = $config->user; 
$dbpassword     = $config->password;
$dbdatabase     = $config->db;
$dbprefix       = $config->dbprefix;
$secret         = $config->secret;

// Get these from your form...

   $username_for_check = 'admin'; // this username should be in your database = change it

   $password_for_check = 'passw'; //this password should be in your database encrypted = change it

//connect to db
   $mysqli = new mysqli($dbhostname,$dbusername,$dbpassword,$dbdatabase);

   if ($result = $mysqli->query('SELECT j.username,j.password FROM '.$dbprefix.'users j WHERE j.username="'.$username_for_check.'" LIMIT 1;')) {

      if ($result->num_rows == 0){
         echo 'Username does not exist.';
      }
      else{
         while ($row = $result->fetch_object()) {

            //Grab username and password from table #__users
            $joomla_user = $row->username;
            $joomla_pass = $row->password;


            $pass_array = explode(':',$row->password);// <== Here not sure!!
            //but it should be the magic behind it.. for me doesn't work  in joomla 3.5 and above apparently as encryption method changed
            //my password does not have a colon in between

            //\\===\ Those are just echos to visually check if the password was matched /==//\\

            echo '[USER:] '.$joomla_user.'<br>';

            echo '[PASS:] '.$joomla_pass.'<br>';

            echo '[HASH:] '.$joomla_hash = $pass_array[0].'<br>';

            echo '[SALT:] '.$joomla_salt = $pass_array[1].'<br>';

            echo '[SECRET:] '.$secret.'<br>'; //secret maybe of help, just put it ready for testing

            echo '[CHECK:] '.md5($password_for_check.$joomla_salt).'<br>';
            //=======================================================================//
         }

         if($joomla_hash == md5($password_for_check.$joomla_salt)){ //Old approch for validating according to various prehistoric posts

            echo 'Username and password combination validated.';

         }
         else{
            echo 'Invalid password for username.';
         }

      }

   }
   else {
     echo 'LOGIN VALIDATION: MySQL Error - '.$mysqli->error;
   }
   //close db
   $mysqli->close();

正在尝试返回匹配项并验证注册用户,然后再继续。

我希望有人在3.5和更高版本上有一个解决方案。

提前感谢

EN

回答

页面原文内容由Stack Overflow提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://stackoverflow.com/questions/44671925

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档