• Heikki Linnakangas's avatar
    Refactor the code for verifying user's password. · e7f051b8
    Heikki Linnakangas authored
    Split md5_crypt_verify() into three functions:
    * get_role_password() to fetch user's password from pg_authid, and check
      its expiration.
    * md5_crypt_verify() to check an MD5 authentication challenge
    * plain_crypt_verify() to check a plaintext password.
    
    get_role_password() will be needed as a separate function by the upcoming
    SCRAM authentication patch set. Most of the remaining functionality in
    md5_crypt_verify() was different for MD5 and plaintext authentication, so
    split that for readability.
    
    While we're at it, simplify the *_crypt_verify functions by using
    stack-allocated buffers to hold the temporary MD5 hashes, instead of
    pallocing.
    
    Reviewed by Michael Paquier.
    
    Discussion: https://www.postgresql.org/message-id/3029e460-d47c-710e-507e-d8ba759d7cbb@iki.fi
    e7f051b8
auth.c 75.3 KB