feature 2727: improved backward compatibility with ['pass_convert']

git-svn-id: http://piwigo.org/svn/trunk@18890 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
plegall 2012-11-02 14:39:01 +00:00
parent a73846717f
commit 26e0ed8fd6

View file

@ -1133,10 +1133,17 @@ function pwg_password_verify($password, $hash, $user_id=null)
{
global $conf, $pwg_hasher;
// If the hash is still md5...
if (strlen($hash) <= 32)
// If the password has not been hashed with the current algorithm.
if (strpos('$P', $hash) !== 0)
{
$check = ($hash == md5($password));
if (!empty($conf['pass_convert']))
{
$check = ($hash == $conf['pass_convert']($password));
}
else
{
$check = ($hash == md5($password));
}
if ($check and isset($user_id) and !$conf['external_authentification'])
{