X-Git-Url: http://git.shadowcat.co.uk/gitweb/gitweb.cgi?a=blobdiff_plain;f=lib%2FCatalyst%2FAuthentication%2FStore%2FLDAP%2FUser.pm;h=636728e4d6497fc4d70efcbcb3c4562a1b33bde4;hb=8fe890e686a125fbb6f70afd6d95a9c6fe00b210;hp=27d0462a7d18b110abdf703085228f9b779c8371;hpb=89ab2886c28994132b9892737764c5e64bd6ab62;p=catagits%2FCatalyst-Authentication-Store-LDAP.git diff --git a/lib/Catalyst/Authentication/Store/LDAP/User.pm b/lib/Catalyst/Authentication/Store/LDAP/User.pm index 27d0462..636728e 100644 --- a/lib/Catalyst/Authentication/Store/LDAP/User.pm +++ b/lib/Catalyst/Authentication/Store/LDAP/User.pm @@ -48,27 +48,33 @@ use base qw( Catalyst::Authentication::User Class::Accessor::Fast ); use strict; use warnings; +use Scalar::Util qw/refaddr/; -our $VERSION = '0.1004'; +our $VERSION = '1.006'; -BEGIN { __PACKAGE__->mk_accessors(qw/user store _ldap_connection_password/) } +BEGIN { __PACKAGE__->mk_accessors(qw/user store/) } use overload '""' => sub { shift->stringify }, fallback => 1; +my %_ldap_connection_passwords; # Store inside-out so that they don't show up + # in dumps.. + =head1 METHODS -=head2 new($store, $user) +=head2 new($store, $user, $c) Takes a L object as $store, and the data structure returned by that class's "get_user" -method as $user. +method as $user. The final argument is an instance of your application, +which is passed along for those wanting to subclass User and perhaps use +models for fetching data. Returns a L object. =cut sub new { - my ( $class, $store, $user ) = @_; + my ( $class, $store, $user, $c ) = @_; return unless $user; @@ -145,9 +151,7 @@ sub check_password { $self->roles($ldap); } # Stash a closure which can be used to retrieve the connection in the users context later. - $self->_ldap_connection_password( sub { $password } ); # Close over - # password to try to ensure it doesn't come out in debug dumps - # or get serialized into sessions etc.. + $_ldap_connection_passwords{refaddr($self)} = $password; return 1; } else { @@ -242,7 +246,7 @@ as, and returns a L object which you can use to do further queries. sub ldap_connection { my $self = shift; $self->store->ldap_bind( undef, $self->ldap_entry->dn, - $self->_ldap_connection_password->() ); + $_ldap_connection_passwords{refaddr($self)} ); } =head2 AUTOLOADed methods @@ -284,6 +288,12 @@ value of user_field (uid by default.) =cut +sub DESTROY { + my $self = shift; + # Don't leak passwords.. + delete $_ldap_connection_passwords{refaddr($self)}; +} + sub AUTOLOAD { my $self = shift;