Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion src/Auth/Events/Event.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
namespace LdapRecord\Auth\Events;

use LdapRecord\LdapInterface;
use SensitiveParameter;

abstract class Event
{
Expand All @@ -24,7 +25,7 @@ abstract class Event
/**
* Constructor.
*/
public function __construct(LdapInterface $connection, ?string $username = null, ?string $password = null)
public function __construct(LdapInterface $connection, ?string $username = null, #[SensitiveParameter] ?string $password = null)
{
$this->connection = $connection;
$this->username = $username;
Expand Down
3 changes: 2 additions & 1 deletion src/Auth/Events/Failed.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
use Exception;
use LdapRecord\Auth\BindException;
use LdapRecord\LdapInterface;
use SensitiveParameter;

class Failed extends Event
{
Expand All @@ -16,7 +17,7 @@ class Failed extends Event
/**
* Constructor.
*/
public function __construct(LdapInterface $connection, ?string $username, ?string $password, BindException $exception)
public function __construct(LdapInterface $connection, ?string $username, #[SensitiveParameter] ?string $password, BindException $exception)
{
parent::__construct($connection, $username, $password);

Expand Down
9 changes: 5 additions & 4 deletions src/Auth/Guard.php
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@
use LdapRecord\ConnectionException;
use LdapRecord\Events\DispatcherInterface;
use LdapRecord\LdapInterface;
use SensitiveParameter;

class Guard
{
Expand Down Expand Up @@ -41,7 +42,7 @@ public function __construct(LdapInterface $connection, DomainConfiguration $conf
* @throws UsernameRequiredException
* @throws PasswordRequiredException
*/
public function attempt(string $username, string $password, bool $stayBound = false): bool
public function attempt(string $username, #[SensitiveParameter] string $password, bool $stayBound = false): bool
{
switch (true) {
case $username === '':
Expand Down Expand Up @@ -75,7 +76,7 @@ public function attempt(string $username, string $password, bool $stayBound = fa
* @throws BindException
* @throws ConnectionException
*/
public function bind(?string $username = null, ?string $password = null): void
public function bind(?string $username = null, #[SensitiveParameter] ?string $password = null): void
{
$this->fireAuthEvent('binding', $username, $password);

Expand Down Expand Up @@ -106,7 +107,7 @@ public function bind(?string $username = null, ?string $password = null): void
*
* @throws ConnectionException
*/
protected function authenticate(?string $username = null, ?string $password = null): bool
protected function authenticate(?string $username = null, #[SensitiveParameter] ?string $password = null): bool
{
if ($this->configuration->get('use_sasl') ?? false) {
return $this->connection->saslBind(
Expand Down Expand Up @@ -151,7 +152,7 @@ public function setDispatcher(?DispatcherInterface $dispatcher = null): void
/**
* Fire an authentication event.
*/
protected function fireAuthEvent(string $name, ?string $username = null, ?string $password = null, ...$args): void
protected function fireAuthEvent(string $name, ?string $username = null, #[SensitiveParameter] ?string $password = null, ...$args): void
{
if (isset($this->events)) {
$event = implode('\\', [Events::class, ucfirst($name)]);
Expand Down
5 changes: 3 additions & 2 deletions src/Connection.php
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@
use LdapRecord\Query\Builder;
use LdapRecord\Query\Cache;
use Psr\SimpleCache\CacheInterface;
use SensitiveParameter;

class Connection
{
Expand Down Expand Up @@ -208,7 +209,7 @@ public function setGuardResolver(Closure $callback): void
* @throws Auth\BindException
* @throws LdapRecordException
*/
public function connect(?string $username = null, ?string $password = null): void
public function connect(?string $username = null, #[SensitiveParameter] ?string $password = null): void
{
$attempt = function () use ($username, $password) {
$this->dispatch(new Events\Connecting($this));
Expand Down Expand Up @@ -334,7 +335,7 @@ public function isolate(Closure $operation): mixed
*
* @throws LdapRecordException
*/
public function changePassword(string $dn, string $oldPassword, string $newPassword): bool|string
public function changePassword(string $dn, #[SensitiveParameter] string $oldPassword, #[SensitiveParameter] string $newPassword): bool|string
{
return $this->isolate(function (Connection $connection) use ($dn, $oldPassword, $newPassword) {
$connection->connect($dn, $oldPassword);
Expand Down
7 changes: 4 additions & 3 deletions src/Ldap.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
use LDAP\Connection as RawLdapConnection;
use Ldap\Result;
use Ldap\ResultEntry;
use SensitiveParameter;

class Ldap implements LdapInterface
{
Expand Down Expand Up @@ -272,7 +273,7 @@ public function parseResult(mixed $result, int &$errorCode = 0, ?string &$dn = n
/**
* {@inheritdoc}
*/
public function bind(?string $dn = null, ?string $password = null, ?array $controls = null): LdapResultResponse
public function bind(?string $dn = null, #[SensitiveParameter] ?string $password = null, ?array $controls = null): LdapResultResponse
{
/** @var \LDAP\Result $result */
$result = $this->executeFailableOperation(function () use ($dn, $password, $controls) {
Expand All @@ -289,7 +290,7 @@ public function bind(?string $dn = null, ?string $password = null, ?array $contr
/**
* {@inheritdoc}
*/
public function saslBind(?string $dn = null, ?string $password = null, array $options = []): bool
public function saslBind(?string $dn = null, #[SensitiveParameter] ?string $password = null, array $options = []): bool
{
return $this->executeFailableOperation(function () use ($dn, $password, $options) {
$options = array_merge([
Expand Down Expand Up @@ -371,7 +372,7 @@ public function modifyBatch(string $dn, array $values): bool
/**
* {@inheritdoc}
*/
public function exopPasswd(string $user = '', string $oldPassword = '', string $newPassword = '', ?array &$controls = null): bool|string
public function exopPasswd(string $user = '', #[SensitiveParameter] string $oldPassword = '', #[SensitiveParameter] string $newPassword = '', ?array &$controls = null): bool|string
{
if (! function_exists('ldap_exop_passwd')) {
throw new LdapRecordException(
Expand Down
7 changes: 4 additions & 3 deletions src/LdapInterface.php
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@

use LDAP\Connection;
use LDAP\Result;
use SensitiveParameter;

/**
* @see https://ldap.com/ldap-oid-reference-guide
Expand Down Expand Up @@ -502,7 +503,7 @@ public function parseResult(mixed $result, int &$errorCode = 0, ?string &$dn = n
*
* @throws LdapRecordException
*/
public function bind(?string $dn = null, ?string $password = null, ?array $controls = null): LdapResultResponse;
public function bind(?string $dn = null, #[SensitiveParameter] ?string $password = null, ?array $controls = null): LdapResultResponse;

/**
* Bind to the LDAP directory using SASL.
Expand All @@ -517,7 +518,7 @@ public function bind(?string $dn = null, ?string $password = null, ?array $contr
* @see https://php.net/manual/en/function.ldap-sasl-bind.php
* @see https://www.iana.org/assignments/sasl-mechanisms/sasl-mechanisms.xhtml
*/
public function saslBind(?string $dn = null, ?string $password = null, array $options = []): bool;
public function saslBind(?string $dn = null, #[SensitiveParameter] ?string $password = null, array $options = []): bool;

/**
* Adds an entry to the current connection.
Expand Down Expand Up @@ -575,7 +576,7 @@ public function modifyBatch(string $dn, array $values): bool;
*
* @throws LdapRecordException
*/
public function exopPasswd(string $user = '', string $oldPassword = '', string $newPassword = '', ?array &$controls = null): bool|string;
public function exopPasswd(string $user = '', #[SensitiveParameter] string $oldPassword = '', #[SensitiveParameter] string $newPassword = '', ?array &$controls = null): bool|string;

/**
* Add attribute values to current attributes.
Expand Down
45 changes: 23 additions & 22 deletions src/Models/Attributes/Password.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
use InvalidArgumentException;
use LdapRecord\LdapRecordException;
use ReflectionMethod;
use SensitiveParameter;

class Password
{
Expand All @@ -17,87 +18,87 @@ class Password
/**
* Make an encoded password for transmission over LDAP.
*/
public static function encode(string $password): string
public static function encode(#[SensitiveParameter] string $password): string
{
return iconv('UTF-8', 'UTF-16LE', '"'.$password.'"');
}

/**
* Make a salted md5 password.
*/
public static function smd5(string $password, ?string $salt = null): string
public static function smd5(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{SMD5}'.static::makeHash($password, 'md5', null, $salt ?? random_bytes(4));
}

/**
* Make a salted SHA password.
*/
public static function ssha(string $password, ?string $salt = null): string
public static function ssha(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{SSHA}'.static::makeHash($password, 'sha1', null, $salt ?? random_bytes(4));
}

/**
* Make a salted SSHA256 password.
*/
public static function ssha256(string $password, ?string $salt = null): string
public static function ssha256(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{SSHA256}'.static::makeHash($password, 'hash', 'sha256', $salt ?? random_bytes(4));
}

/**
* Make a salted SSHA384 password.
*/
public static function ssha384(string $password, ?string $salt = null): string
public static function ssha384(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{SSHA384}'.static::makeHash($password, 'hash', 'sha384', $salt ?? random_bytes(4));
}

/**
* Make a salted SSHA512 password.
*/
public static function ssha512(string $password, ?string $salt = null): string
public static function ssha512(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{SSHA512}'.static::makeHash($password, 'hash', 'sha512', $salt ?? random_bytes(4));
}

/**
* Make a non-salted SHA password.
*/
public static function sha(string $password): string
public static function sha(#[SensitiveParameter] string $password): string
{
return '{SHA}'.static::makeHash($password, 'sha1');
}

/**
* Make a non-salted SHA256 password.
*/
public static function sha256(string $password): string
public static function sha256(#[SensitiveParameter] string $password): string
{
return '{SHA256}'.static::makeHash($password, 'hash', 'sha256');
}

/**
* Make a non-salted SHA384 password.
*/
public static function sha384(string $password): string
public static function sha384(#[SensitiveParameter] string $password): string
{
return '{SHA384}'.static::makeHash($password, 'hash', 'sha384');
}

/**
* Make a non-salted SHA512 password.
*/
public static function sha512(string $password): string
public static function sha512(#[SensitiveParameter] string $password): string
{
return '{SHA512}'.static::makeHash($password, 'hash', 'sha512');
}

/**
* Make a non-salted md5 password.
*/
public static function md5(string $password): string
public static function md5(#[SensitiveParameter] string $password): string
{
return '{MD5}'.static::makeHash($password, 'md5');
}
Expand All @@ -110,7 +111,7 @@ public static function md5(string $password): string
*
* @throws LdapRecordException
*/
public static function argon2i(string $password): string
public static function argon2i(#[SensitiveParameter] string $password): string
{
if (! defined('PASSWORD_ARGON2I')) {
throw new LdapRecordException('Argon2i hashing is not supported by this PHP build.');
Expand All @@ -127,7 +128,7 @@ public static function argon2i(string $password): string
*
* @throws LdapRecordException
*/
public static function argon2id(string $password): string
public static function argon2id(#[SensitiveParameter] string $password): string
{
if (! defined('PASSWORD_ARGON2ID')) {
throw new LdapRecordException('Argon2id hashing is not supported by this PHP build.');
Expand All @@ -139,39 +140,39 @@ public static function argon2id(string $password): string
/**
* Make a non-salted NThash password.
*/
public static function nthash(string $password): string
public static function nthash(#[SensitiveParameter] string $password): string
{
return '{NTHASH}'.strtoupper(hash('md4', iconv('UTF-8', 'UTF-16LE', $password)));
}

/**
* Crypt password with an MD5 salt.
*/
public static function md5Crypt(string $password, ?string $salt = null): string
public static function md5Crypt(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{CRYPT}'.static::makeCrypt($password, static::CRYPT_SALT_TYPE_MD5, $salt);
}

/**
* Crypt password with a SHA256 salt.
*/
public static function sha256Crypt(string $password, ?string $salt = null): string
public static function sha256Crypt(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{CRYPT}'.static::makeCrypt($password, static::CRYPT_SALT_TYPE_SHA256, $salt);
}

/**
* Crypt a password with a SHA512 salt.
*/
public static function sha512Crypt(string $password, ?string $salt = null): string
public static function sha512Crypt(#[SensitiveParameter] string $password, ?string $salt = null): string
{
return '{CRYPT}'.static::makeCrypt($password, static::CRYPT_SALT_TYPE_SHA512, $salt);
}

/**
* Make a new password hash.
*/
protected static function makeHash(string $password, string $method, ?string $algo = null, ?string $salt = null): string
protected static function makeHash(#[SensitiveParameter] string $password, string $method, ?string $algo = null, ?string $salt = null): string
{
$params = $algo ? [$algo, $password.$salt] : [$password.$salt];

Expand All @@ -181,7 +182,7 @@ protected static function makeHash(string $password, string $method, ?string $al
/**
* Make a hashed password.
*/
protected static function makeCrypt(string $password, int $type, ?string $salt = null): string
protected static function makeCrypt(#[SensitiveParameter] string $password, int $type, ?string $salt = null): string
{
return crypt($password, $salt ?? static::makeCryptSalt($type));
}
Expand Down Expand Up @@ -221,7 +222,7 @@ protected static function makeCryptPrefixAndLength(int $type): array
/**
* Attempt to retrieve the hash method used for the password.
*/
public static function getHashMethod(string $password): ?string
public static function getHashMethod(#[SensitiveParameter] string $password): ?string
{
if (! preg_match('/^\{(\w+)\}/', $password, $matches)) {
return null;
Expand All @@ -233,7 +234,7 @@ public static function getHashMethod(string $password): ?string
/**
* Attempt to retrieve the hash method and algorithm used for the password.
*/
public static function getHashMethodAndAlgo(string $password): ?array
public static function getHashMethodAndAlgo(#[SensitiveParameter] string $password): ?array
{
if (! preg_match('/^\{(\w+)\}\$([0-9a-z]{1})\$/', $password, $matches)) {
return null;
Expand All @@ -247,7 +248,7 @@ public static function getHashMethodAndAlgo(string $password): ?array
*
* @throws LdapRecordException
*/
public static function getSalt(string $encryptedPassword): string
public static function getSalt(#[SensitiveParameter] string $encryptedPassword): string
{
// crypt() methods.
if (preg_match('/^\{(\w+)\}(\$.*\$).*$/', $encryptedPassword, $matches)) {
Expand Down
Loading
Loading