ExtCookieAuth allows to configure & setup cookies, which could be used
to check logged in user's authentication of drupal for any external file/webservice,
which is not possible to use within drupal.
After enabling this module site administrators are then able to
setup a cookie's name & key (which is used to encrypt/decrypt user information).
-- CONFIGURATION --
* Configure at Administration » Configuration » ExternalAuth.
-- USAGE --
* Site Administrator can enter a cookie & key name in the configuration form
* then Developers can use it as follow
$cipher = 'AES-256-CBC';
$iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length($cipher));
list($_COOKIE['yourscookie'], $iv) = explode('::', base64_decode($_COOKIE['yourscookie']), 2);
$arr = openssl_decrypt($_COOKIE['yourscookie'], $cipher, 'yourskey', 0, $iv);
$userinfo = (unserialize($arr));
print_r($userinfo);
Project Page URL:-
https://www.drupal.org/sandbox/khurrami/2839099
Git Clone:-
git clone --branch 7.x-1.x https://git.drupal.org/sandbox/khurrami/2839099.git extcookieauth
Manual reviews of other projects:
https://www.drupal.org/node/2856297#comment-11964543
https://www.drupal.org/node/2857654#comment-11974956
https://www.drupal.org/node/2855845#comment-11974974
https://www.drupal.org/node/2856115#comment-11985055
https://www.drupal.org/node/2830563#comment-11985081
https://www.drupal.org/node/2840555#comment-11985086
Comments
Comment #2
PA robot commentedThere are some errors reported by automated review tools, did you already check them? See http://pareview.sh/pareview/httpsgitdrupalorgsandboxkhurrami2839099git
Fixed the git clone URL in the issue summary for non-maintainer users.
We are currently quite busy with all the project applications and we prefer projects with a review bonus. Please help reviewing and put yourself on the high priority list, then we will take a look at your project right away :-)
Also, you should get your friends, colleagues or other community members involved to review this application. Let them go through the review checklist and post a comment that sets this issue to "needs work" (they found some problems with the project) or "reviewed & tested by the community" (they found no major flaws).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #3
ankush_03Hi khurrami,
Below are my manual review :
1. Use drupal coding standard for proper commenting change
to
Implements externalauth_form_validate().2. Add
hook_helpin your module file.3. use
t()function for title.4. it's good practice to add modulename with function name :
change
function encrypt()tofunction externalauth_encrypt()5. change
to
Comment #4
khurrami commented@agautam Thanks a lot for your review. for your #3 i have checked the code with code sniffer which recommends to avoid t() in menu hook for title. Other points (#1, #2, #4 & #5 i have fixed.
Again Thanks
Comment #5
PA robot commentedClosing due to lack of activity. If you are still working on this application, you should fix all known problems and then set the status to "Needs review". (See also the project application workflow).
I'm a robot and this is an automated message from Project Applications Scraper.
Comment #6
khurrami commentedComment #7
khurrami commentedComment #8
khurrami commentedComment #9
khurrami commentedComment #10
klausiRemoving review bonus tag, you have not done any manual review, you just posted the output of an automated review tool. Make sure to read through the source code of the other projects, as requested on the review bonus page.
This application is currently closed, did you mean to reopen it again? If so please set it to "needs review".
Comment #11
khurrami commentedComment #12
shamas41 commentedHi @khurrami
I have reviewed your module below are my initial findings
Manual Review
1. Found some Notices when I am on admin page of extCookieAuth
Notice: Use of undefined constant yourskey - assumed 'yourskey' in extcookieauth_form() (line 54 of /Users/shamas_mac/Sites/drtest/sites/all/modules/extcookieauth/extcookieauth.module).
Notice: Use of undefined constant yourscookie - assumed 'yourscookie' in extcookieauth_form() (line 61 of /Users/shamas_mac/Sites/drtest/sites/all/modules/extcookieauth/extcookieauth.module)
Automatic Review
Review of the 7.x-1.x branch (commit a2d8f4b):
Bad line endings were found, always use unix style terminators. See https://www.drupal.org/coding-standards#indenting
Remove all old CVS $Id tags, they are not needed anymore.
extcookieauth.info:1:; $Id$Coder Sniffer has found some issues with your code (please check the Drupal coding standards).
DrupalPractice has found some issues with your code, but could be false positives.
Please resolve these issues
Comment #13
khurrami commentedHi @ Shamas
Thanks for your review i have fixed the items listed by you
Thanks
Comment #14
khurrami commentedComment #15
khurrami commentedComment #16
khurrami commentedComment #17
khurrami commentedComment #18
klausiRemoving review bonus tag, you have not done all manual reviews, you just posted the output of an automated review tool. Make sure to read through the source code of the other projects, as requested on the review bonus page.
Comment #19
khurrami commentedComment #20
khurrami commentedComment #21
yogeshmpawarComment #22
sumit.prajapati commentedHi khurrami,
Please add hook_uninstall in install file for removing variable extcookieauthkey extcookieauthcookies.
Comment #23
khurrami commentedThanks @Sumit
I have work on it and updated
Comment #24
klausiGit errors:
Review of the 7.x-1.x branch (commit 327ca62):
This automated report was generated with PAReview.sh, your friendly project application review script. You can also use the online version to check your project. You have to get a review bonus to get a review from me.
manual review:
Removing review bonus tag, you can add it again if you have done another 3 reviews of other projects.
Comment #25
klausiSending out password hashes can probably be classified as security issue, adding tag. And please don't remove the security tag, we keep that for statistics and to show examples of security problems.
Comment #26
khurrami commentedComment #27
khurrami commentedComment #28
khurrami commentedComment #29
khurrami commentedHi klausi,
Thanks for your time
I have updated the items you mentioned
Comment #30
khurrami commentedComment #31
khurrami commentedComment #32
khurrami commentedComment #33
sumit.prajapati commentedHi khurrami,
Ok, Now its updated.
Comment #34
Kostya19 commentedI made a manual review. Everything fine, except some minor issues:
1. You can add the line:
configure = admin/config/extcookieauth/settingsinextcookieauth.infoto let users move to settings from module page.2. Bad line endings were found in
extcookieauth.info, always use unix style terminators.3. Wrong doc block for functions
extcookieauth_form()andextcookieauth_form_validate(). See https://www.drupal.org/docs/develop/coding-standards/api-documentation-a...4. Wrong doc block for function
extcookieauth_encrypt(). Particularly, should be @param and @return tags. See https://www.drupal.org/docs/develop/coding-standards/api-documentation-a...Comment #35
avpadernoThank you for your contribution!
I am going to update your account so you can opt into security advisory coverage now.
These are some recommended readings to help with excellent maintainership:
You can find more contributors chatting on the IRC #drupal-contribute channel. So, come hang out and stay involved.
Thank you, also, for your patience with the review process.
Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.
I thank all the dedicated reviewer(s) as well.
Comment #36
avpaderno