Movatterモバイル変換


[0]ホーム

URL:



Facebook
Postgres Pro
Facebook
Downloads
F.8. chkpass
Prev UpAppendix F. Additional Supplied ModulesHome Next

F.8. chkpass

This module implements a data typechkpass that is designed for storing encrypted passwords. Each password is automatically converted to encrypted form upon entry, and is always stored encrypted. To compare, simply compare against a clear text password and the comparison function will encrypt it before comparing.

There are provisions in the code to report an error if the password is determined to be easily crackable. However, this is currently just a stub that does nothing.

If you precede an input string with a colon, it is assumed to be an already-encrypted password, and is stored without further encryption. This allows entry of previously-encrypted passwords.

On output, a colon is prepended. This makes it possible to dump and reload passwords without re-encrypting them. If you want the encrypted password without the colon then use theraw() function. This allows you to use the type with things like Apache'sAuth_PostgreSQL module.

The encryption uses the standard Unix functioncrypt(), and so it suffers from all the usual limitations of that function; notably that only the first eight characters of a password are considered.

Note that thechkpass data type is not indexable.

Sample usage:

test=# create table test (p chkpass);CREATE TABLEtest=# insert into test values ('hello');INSERT 0 1test=# select * from test;       p---------------- :dVGkpXdOrE3ko(1 row)test=# select raw(p) from test;      raw--------------- dVGkpXdOrE3ko(1 row)test=# select p = 'hello' from test; ?column?---------- t(1 row)test=# select p = 'goodbye' from test; ?column?---------- f(1 row)

F.8.1. Author

D'Arcy J.M. Cain (<darcy@druid.net>)


Prev Up Next
F.7. btree_gist Home F.9. citext
epubpdf
Go to PostgreSQL 10
By continuing to browse this website, you agree to the use of cookies. Go toPrivacy Policy.

[8]ページ先頭

©2009-2025 Movatter.jp