pwd. Sets user if applicable, returns bool function yourls_check_username_password() { global $yourls_user_passwords; if( $yourls_user_passwords[ $_REQUEST['username'] ] == $_REQUEST['password'] ) { yourls_set_user( $_REQUEST['username'] ); return true; } return false; } // Check auth against encrypted COOKIE data. Sets user if applicable, returns bool function yourls_check_auth_cookie() { global $yourls_user_passwords; foreach( $yourls_user_passwords as $valid_user => $valid_password ) { if( yourls_salt($valid_user) == $_COOKIE['yourls_username'] && yourls_salt($valid_password) == $_COOKIE['yourls_password'] ) { yourls_set_user( $valid_user ); return true; } } return false; } // Check auth against signature and timestamp. Sets user if applicable, returns bool function yourls_check_signature_timestamp() { // Timestamp in PHP : time() // Timestamp in JS: parseInt(new Date().getTime() / 1000) global $yourls_user_passwords; foreach( $yourls_user_passwords as $valid_user => $valid_password ) { if ( ( md5( $_REQUEST['timestamp'].yourls_auth_signature( $valid_user ) ) == $_REQUEST['signature'] or md5( yourls_auth_signature( $valid_user ).$_REQUEST['timestamp'] ) == $_REQUEST['signature'] ) && yourls_check_timestamp( $_REQUEST['timestamp'] ) ) { yourls_set_user( $valid_user ); return true; } } return false; } // Check auth against signature. Sets user if applicable, returns bool function yourls_check_signature() { global $yourls_user_passwords; foreach( $yourls_user_passwords as $valid_user => $valid_password ) { if ( yourls_auth_signature( $valid_user ) == $_REQUEST['signature'] ) { yourls_set_user( $valid_user ); return true; } } return false; } // Generate secret signature hash function yourls_auth_signature( $username = false ) { if( !$username && defined('YOURLS_USER') ) { $username = YOURLS_USER; } return ( $username ? substr( yourls_salt( $username ), 0, 10 ) : 'Cannot generate auth signature: no username' ); } // Check a timestamp is from the past and not too old function yourls_check_timestamp( $time ) { $now = time(); return ( $now >= $time && ceil( $now - $time ) < YOURLS_NONCE_LIFE ); } // Store new cookie. No $user will delete the cookie. function yourls_store_cookie( $user = null ) { if( !$user ) { $pass = null; $time = time() - 3600; } else { global $yourls_user_passwords; if( isset($yourls_user_passwords[$user]) ) { $pass = $yourls_user_passwords[$user]; } else { die('Stealing cookies?'); // This should never happen } $time = time() + YOURLS_COOKIE_LIFE; } if ( !headers_sent() ) { setcookie('yourls_username', yourls_salt( $user ), $time, '/' ); setcookie('yourls_password', yourls_salt( $pass ), $time, '/' ); } } // Set user name function yourls_set_user( $user ) { if( !defined('YOURLS_USER') ) define('YOURLS_USER', $user); }