ExtCookieAuth allows to configure & setup cookies, which could be used
to check logged in user's authentication of drupal for any external file/webservice,
which is not possible to use within drupal.

After enabling this module site administrators are then able to
setup a cookie's name & key (which is used to encrypt/decrypt user information).

-- CONFIGURATION --

* Configure at Administration » Configuration » ExternalAuth.

-- USAGE --

* Site Administrator can enter a cookie & key name in the configuration form
* then Developers can use it as follow
$cipher = 'AES-256-CBC';
$iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length($cipher));
list($_COOKIE['yourscookie'], $iv) = explode('::', base64_decode($_COOKIE['yourscookie']), 2);
$arr = openssl_decrypt($_COOKIE['yourscookie'], $cipher, 'yourskey', 0, $iv);
$userinfo = (unserialize($arr));
print_r($userinfo);

Project Page URL:-
https://www.drupal.org/sandbox/khurrami/2839099

Git Clone:-
git clone --branch 7.x-1.x https://git.drupal.org/sandbox/khurrami/2839099.git extcookieauth

Manual reviews of other projects:
https://www.drupal.org/node/2856297#comment-11964543
https://www.drupal.org/node/2857654#comment-11974956
https://www.drupal.org/node/2855845#comment-11974974
https://www.drupal.org/node/2856115#comment-11985055
https://www.drupal.org/node/2830563#comment-11985081
https://www.drupal.org/node/2840555#comment-11985086

Comments

khurrami created an issue. See original summary.

PA robot’s picture

Issue summary: View changes
Status: Needs review » Needs work

There are some errors reported by automated review tools, did you already check them? See http://pareview.sh/pareview/httpsgitdrupalorgsandboxkhurrami2839099git

Fixed the git clone URL in the issue summary for non-maintainer users.

We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)

Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).

I'm a robot and this is an automated message from Project Applications Scraper.

ankush_03’s picture

Hi khurrami,

Below are my manual review :

1. Use drupal coding standard for proper commenting change

/**
 * Form validation.
 */

to Implements externalauth_form_validate().

2. Add hook_help in your module file.

3. use t() function for title.

4. it's good practice to add modulename with function name :
change function encrypt() to function externalauth_encrypt()

5. change

/**
 * Encryption function.
 */

to

/**
 * Implements externalauth_encrypt().
 */
khurrami’s picture

@agautam Thanks a lot for your review. for your #3 i have checked the code with code sniffer which recommends to avoid t() in menu hook for title. Other points (#1, #2, #4 & #5 i have fixed.

Again Thanks

PA robot’s picture

Status: Needs work » Closed (won't fix)

Closing due to lack of activity. If you are still working on this application, you should fix all known problems and then set the status to "Needs review". (See also the project application workflow).

I'm a robot and this is an automated message from Project Applications Scraper.

khurrami’s picture

Issue summary: View changes
Issue tags: +PAreview: review bonus
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
klausi’s picture

Issue summary: View changes
Status: Closed (won't fix) » Postponed (maintainer needs more info)
Issue tags: -PAreview: review bonus

Removing review bonus tag, you have not done any manual review, you just posted the output of an automated review tool. Make sure to read through the source code of the other projects, as requested on the review bonus page.

This application is currently closed, did you mean to reopen it again? If so please set it to "needs review".

khurrami’s picture

Status: Postponed (maintainer needs more info) » Needs review
shamas41’s picture

Status: Needs review » Needs work

Hi @khurrami

I have reviewed your module below are my initial findings

Manual Review

1. Found some Notices when I am on admin page of extCookieAuth
Notice: Use of undefined constant yourskey - assumed 'yourskey' in extcookieauth_form() (line 54 of /Users/shamas_mac/Sites/drtest/sites/all/modules/extcookieauth/extcookieauth.module).

Notice: Use of undefined constant yourscookie - assumed 'yourscookie' in extcookieauth_form() (line 61 of /Users/shamas_mac/Sites/drtest/sites/all/modules/extcookieauth/extcookieauth.module)

Individual user account
Yes: Follows the guidelines for individual user accounts.
No duplication
Yes: Does not cause module duplication and fragmentation.
Master Branch
Yes: Follows the guidelines for master branch.
Licensing
Yes: Follows the licensing requirements
3rd party code
Yes: Follows the guidelines for 3rd party code.
README.txt/README.md
Yes: Follows the guidelines for in-project documentation and the README Template.
Code long/complex enough for review
Yes: Follows the guidelines for project length and complexity.

Automatic Review

Review of the 7.x-1.x branch (commit a2d8f4b):

Bad line endings were found, always use unix style terminators. See https://www.drupal.org/coding-standards#indenting

./extcookieauth.info: ASCII text, with CRLF line terminators
extcookieauth.info

Remove all old CVS $Id tags, they are not needed anymore.

extcookieauth.info:1:; $Id$
Coder Sniffer has found some issues with your code (please check the Drupal coding standards).

FILE: /root/repos/pareviewsh/pareview_temp/README.txt
----------------------------------------------------------------------
FOUND 0 ERRORS AND 2 WARNINGS AFFECTING 2 LINES
----------------------------------------------------------------------
5 | WARNING | Line exceeds 80 characters; contains 84 characters
20 | WARNING | Line exceeds 80 characters; contains 88 characters
----------------------------------------------------------------------

FILE: /root/repos/pareviewsh/pareview_temp/extcookieauth.info
----------------------------------------------------------------------
FOUND 1 ERROR AFFECTING 1 LINE
----------------------------------------------------------------------
5 | ERROR | [x] Expected 1 newline at end of file; 0 found
----------------------------------------------------------------------
PHPCBF CAN FIX THE 1 MARKED SNIFF VIOLATIONS AUTOMATICALLY
----------------------------------------------------------------------

Time: 64ms; Memory: 6Mb

DrupalPractice has found some issues with your code, but could be false positives.

FILE: /root/repos/pareviewsh/pareview_temp/extcookieauth.module
--------------------------------------------------------------------------
FOUND 0 ERRORS AND 1 WARNING AFFECTING 1 LINE
--------------------------------------------------------------------------
29 | WARNING | The administration menu callback should probably use
| | "administer site configuration" - which implies the user
| | can change something - rather than "access administration
| | pages" which is about viewing but not changing
| | configurations.
--------------------------------------------------------------------------

Time: 15ms; Memory: 4Mb

Please resolve these issues

khurrami’s picture

Status: Needs work » Needs review

Hi @ Shamas

Thanks for your review i have fixed the items listed by you

Thanks

khurrami’s picture

Issue tags: +PAreview: review bonus
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
klausi’s picture

Issue summary: View changes
Issue tags: -PAreview: review bonus

Removing review bonus tag, you have not done all manual reviews, you just posted the output of an automated review tool. Make sure to read through the source code of the other projects, as requested on the review bonus page.

khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
Issue tags: +PAreview: review bonus
yogeshmpawar’s picture

Title: ExtCookieAuth[D7] » [D7] ExtCookieAuth
sumit.prajapati’s picture

Hi khurrami,

Please add hook_uninstall in install file for removing variable extcookieauthkey extcookieauthcookies.

khurrami’s picture

Thanks @Sumit

I have work on it and updated

klausi’s picture

Status: Needs review » Needs work
Issue tags: -PAreview: review bonus

Git errors:

Review of the 7.x-1.x branch (commit 327ca62):

  • Bad line endings were found, always use unix style terminators. See https://www.drupal.org/coding-standards#indenting
    ./extcookieauth.info:    ASCII text, with CRLF line terminators
    extcookieauth.info
    
  • Coder Sniffer has found some issues with your code (please check the Drupal coding standards).
    FILE: /home/klausi/pareview_temp/extcookieauth.install
    ----------------------------------------------------------------------
    FOUND 1 ERROR AFFECTING 1 LINE
    ----------------------------------------------------------------------
     1 | ERROR | [x] Missing file doc comment
    ----------------------------------------------------------------------
    PHPCBF CAN FIX THE 1 MARKED SNIFF VIOLATIONS AUTOMATICALLY
    ----------------------------------------------------------------------
    
  • No automated test cases were found, did you consider writing Simpletests or PHPUnit tests? This is not a requirement but encouraged for professional software development.

This automated report was generated with PAReview.sh, your friendly project application review script. You can also use the online version to check your project. You have to get a review bonus to get a review from me.

manual review:

  1. "File updated" is a bad git commit message. You should describe what the change was about. See https://www.drupal.org/node/52287
  2. extcookieauth_form(): doc block is wrong, see https://www.drupal.org/docs/develop/coding-standards/api-documentation-a... . Looks like all your non-hook doc blocks are wrong where you just repeat the function name. Can you describe what the function does instead?
  3. extcookieauth_user_login(): you are sending out the full user object including the password hash! Password hashes should never be transmitted externally. I think that is currently an application blocker. You should only send out a white list of properties on the user that you really want to send out.
  4. Do not use mcrypt_encrypt(), it is deprecated as of PHP 7.1. See also https://paragonie.com/blog/2015/05/if-you-re-typing-word-mcrypt-into-you...
  5. https://paragonie.com/blog/2015/05/using-encryption-and-authentication-c... has also other suggestions beyond openssl if you want to go so far.

Removing review bonus tag, you can add it again if you have done another 3 reviews of other projects.

klausi’s picture

Issue tags: +PAreview: security

Sending out password hashes can probably be classified as security issue, adding tag. And please don't remove the security tag, we keep that for statistics and to show examples of security problems.

khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Hi klausi,

Thanks for your time

I have updated the items you mentioned

khurrami’s picture

Status: Needs work » Needs review
Issue tags: +PAreview: review bonus
khurrami’s picture

Issue summary: View changes
khurrami’s picture

Issue summary: View changes
sumit.prajapati’s picture

Hi khurrami,

Ok, Now its updated.

Kostya19’s picture

Status: Needs review » Reviewed & tested by the community

I made a manual review. Everything fine, except some minor issues:
1. You can add the line: configure = admin/config/extcookieauth/settings in extcookieauth.info to let users move to settings from module page.
2. Bad line endings were found in extcookieauth.info, always use unix style terminators.
3. Wrong doc block for functions extcookieauth_form() and extcookieauth_form_validate(). See https://www.drupal.org/docs/develop/coding-standards/api-documentation-a...
4. Wrong doc block for function extcookieauth_encrypt(). Particularly, should be @param and @return tags. See https://www.drupal.org/docs/develop/coding-standards/api-documentation-a...

avpaderno’s picture

Assigned: Unassigned » avpaderno
Status: Reviewed & tested by the community » Fixed

Thank you for your contribution!

I am going to update your account so you can opt into security advisory coverage now.

These are some recommended readings to help with excellent maintainership:

You can find more contributors chatting on the IRC #drupal-contribute channel. So, come hang out and stay involved.

Thank you, also, for your patience with the review process.
Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.

I thank all the dedicated reviewer(s) as well.

avpaderno’s picture

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.